Malicious code in dolyame-ui-clickoutsidehoc (npm)
The npm package dolyame-ui-clickoutsidehoc version 35.8.1 is a malicious package masquerading as a legitimate UI utility. Upon requiring the package, it loads obfuscated code that assembles hostnames to download a platform-specific executable from Cloudflare Workers domains and fallback DNS TXT covert channels. The executable is written to temporary directories under disguised names, given executable permissions, and spawned detached to run attacker-controlled native code on the host system. This package contains no legitimate UI functionality and acts as a dropper for malicious native code.
AI Analysis
Technical Summary
The dolyame-ui-clickoutsidehoc npm package (version 35.8.1) contains obfuscated malicious code that, when imported, dynamically constructs hostnames to fetch a platform-specific binary from Cloudflare Workers-hosted URLs and DNS TXT record fallbacks. It writes this binary to the system's temporary directory under disguised filenames, sets executable permissions, and executes it detached via shell commands. The package name mimics a legitimate UI higher-order component utility but instead functions as a dropper for attacker-controlled native code, enabling remote code execution on any host that installs or imports this package.
Potential Impact
Hosts that install or import the affected version of this package will execute attacker-controlled native code with the privileges of the user running the Node.js process. This can lead to full system compromise, data theft, persistence, or further malicious activity. The package does not provide any legitimate functionality, indicating it is solely designed for malicious purposes.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and avoid installing or importing the dolyame-ui-clickoutsidehoc package, specifically version 35.8.1. Conduct a thorough investigation for any signs of compromise if this package was used. Use trusted sources and verify package authenticity before installation. Monitor for updates from the package repository or security advisories for any official remediation.
Malicious code in dolyame-ui-clickoutsidehoc (npm)
Description
The npm package dolyame-ui-clickoutsidehoc version 35.8.1 is a malicious package masquerading as a legitimate UI utility. Upon requiring the package, it loads obfuscated code that assembles hostnames to download a platform-specific executable from Cloudflare Workers domains and fallback DNS TXT covert channels. The executable is written to temporary directories under disguised names, given executable permissions, and spawned detached to run attacker-controlled native code on the host system. This package contains no legitimate UI functionality and acts as a dropper for malicious native code.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dolyame-ui-clickoutsidehoc npm package (version 35.8.1) contains obfuscated malicious code that, when imported, dynamically constructs hostnames to fetch a platform-specific binary from Cloudflare Workers-hosted URLs and DNS TXT record fallbacks. It writes this binary to the system's temporary directory under disguised filenames, sets executable permissions, and executes it detached via shell commands. The package name mimics a legitimate UI higher-order component utility but instead functions as a dropper for attacker-controlled native code, enabling remote code execution on any host that installs or imports this package.
Potential Impact
Hosts that install or import the affected version of this package will execute attacker-controlled native code with the privileges of the user running the Node.js process. This can lead to full system compromise, data theft, persistence, or further malicious activity. The package does not provide any legitimate functionality, indicating it is solely designed for malicious purposes.
Defensive Guidance
No official patch or remediation is currently documented. Users should immediately remove and avoid installing or importing the dolyame-ui-clickoutsidehoc package, specifically version 35.8.1. Conduct a thorough investigation for any signs of compromise if this package was used. Use trusted sources and verify package authenticity before installation. Monitor for updates from the package repository or security advisories for any official remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13558
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a75f712bf8831d53984fbb1
Added to database: 08/07/2026, 15:17:38 UTC
Last enriched: 08/07/2026, 15:43:45 UTC
Last updated: 09/18/2026, 02:04:23 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.