dolyame-ui-grid @35.7.4
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 10:51 AM UTC
OSV ID
MAL-2026-13157
Ecosystem
npm
Summary
On require('dolyame-ui-grid'), index.js loads _polyfill.js which selects a platform-specific asset, downloads a binary from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) with DNS-TXT chunked fallbacks under *.dl.wel1.ru (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), writes it to /tmp or the Windows Temp directory under a disguised name (.cache_<rand> or dotnet_diag_<rand>.exe), chmods it 0755, and spawns it detached via spawn('/bin/sh') or spawn('cmd'). Destination hostnames are assembled at runtime by.join('') on split string fragments, and a.analytics_state mtime file gates re-execution cadence, with comments framing the code as 'telemetry'/'analytics'. A parallel dropper implementation in lib/telemetry.js (base64-decoded chunks, chmodSync 0755, cp.spawn('/bin/sh',['-c', filePath+' &'])) is present but not reachable from the main require graph. The download hosts are unrelated to the package publisher, the fetched bytes are opaque and unverified, and execution happens unconditionally on module load.
Source: amazon-inspector (f21d1f60c7f97ffdc8e698c9804d9d9116f286be7a026a9c90f6e4a1858dea18)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.