-= Per source details. Do not edit below this line.=-
On require of the package's main entry, _compat.js reconstructs Cloudflare Workers hostnames (oob-worker.cf99-9b3.workers.dev, cf100-416.workers.dev, cf101-adf.workers.dev, cf103-070.workers.dev) and a DNS-TXT fallback discovery host (sdk.dl.wel1.ru) from split string arrays joined at runtime, downloads a platform-specific binary via https.get, writes it under /tmp or %TEMP% with disguised names (dotnetdiag<rand>.exe,.cache_<rand>), chmods 0o755, and spawns it detached via /bin/sh -c or cmd. Staging paths and destinations are runtime-assembled to evade literal string matching, and the payload uses cover-story naming resembling system diagnostics. The package presents itself as a UI table toolkit, which has no need for native binary downloads or subprocess execution.
{
"malicious-packages-origins": [
{
"versions": [
"35.5.4"
],
"id": "IN-MAL-2026-015592",
"import_time": "2026-08-05T15:19:59.502129449Z",
"modified_time": "2026-08-05T15:09:59Z",
"source": "amazon-inspector",
"sha256": "ed24a0ae9dfa9dd545fde1200d967a5625a2daf28ada90efb2ad78fe5bfdc73e"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-2Rdw/wDsqSxPT1K/+UK9AnkwRQ7zbzl05nqyyHzCY4uZf+fy06Q9EO7MDMbxB0YlT32iKJByNu0RiSQw9Zs+8Q==",
"sha1": "e132ee9e6d4e9466f21d5416e975b35dd1c84de0"
},
"filename": "dolyame-ui-table-35.5.4.tgz"
}
],
"evidence_files": [
{
"path": "_compat.js",
"tlsh": "65a1b95a12aa701d4bb097e4c61b4426f69bf6533380d6c1fb9ca9984f761248372efc",
"sha256": "9cd45a630fa67a736fd7c02d326fd27a97b09216b532e5553ba48500aa4178ea"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dolyame-ui-table/MAL-2026-13189.json"