npm

dolyame-ui-confirmation @35.3.3

Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 1:06 AM UTC

Malicious

OSV ID

MAL-2026-13148

Ecosystem

npm

Summary

dolyame-ui-confirmation@35.3.3 ships a _shim.js that is require()d from index.js at module load. On import, _shim.js detects the host OS/architecture, downloads a native binary from one of three Cloudflare Workers hosts whose names are assembled by joining split substrings at runtime (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru whose labels are similarly reconstructed. The downloaded bytes are written to /tmp or %TEMP% under a decoy name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on POSIX), chmod 0755 on POSIX, and executed detached via cmd.exe /c start or /bin/sh -c fp+' &'. A /tmp/.analytics_state marker throttles reruns. lib/telemetry.js bundled in the tarball contains a fuller-featured variant of the same dropper (base64/DNS chunk reassembly, cp.spawn('/bin/sh', ['-c', filePath+' &']), fs['chmod'+'Sync'] with 0755). The obfuscation of destinations, decoy filenames, cover comments referencing 'CDN compatibility' and 'analytics_state', and the mismatch with the package's stated React-UI purpose are all consistent with a supply-chain dropper. Installing or importing this package fetches and executes an attacker-controlled native binary on the installer's machine.

Source: amazon-inspector (dba60f94522cc371a13cce00e6a8e51678812f3f50f3e577fd5e9275295a72e0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.