Malicious code in dolyame-ui-inputcard (npm)
The npm package dolyame-ui-inputcard version 35.8.1 contains malicious code that, upon being required, downloads and executes an opaque binary from obfuscated Cloudflare Workers hosts. This binary is saved to a temporary directory, given executable permissions, and run detached from the main process. The package disguises this behavior by using runtime string concatenation to evade static detection and mimics a Sentry-style APM SDK, which is unrelated to its stated UI-input-card functionality.
AI Analysis
Technical Summary
The dolyame-ui-inputcard npm package version 35.8.1 includes malicious code in _shim.js and lib/telemetry.js that selects a platform-specific asset and fetches an opaque binary from one of three obfuscated Cloudflare Workers hosts with a DNS-TXT chunked-base64 fallback via *.dl.wel1.ru. This binary is written to a temporary file path (/var/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe), permissions are set to executable (chmod 0755), and it is spawned detached via shell commands (/bin/sh -c or cmd). The package uses runtime string operations to construct endpoint hostnames and Node.js API names to evade static scanners. This behavior is unrelated to the package's declared purpose as a UI input card component.
Potential Impact
This malicious behavior allows the package to execute arbitrary code on the host system without user consent or verification, potentially leading to system compromise or unauthorized actions. The lack of hash or signature verification for the downloaded binary increases risk. However, there are no known exploits in the wild reported at this time.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using version 35.8.1 of dolyame-ui-inputcard. Remove this package from projects and replace it with a trusted alternative. Monitor vendor advisories and npm security notices for updates or official fixes. Since this is not a cloud service, remediation depends on user action.
Malicious code in dolyame-ui-inputcard (npm)
Description
The npm package dolyame-ui-inputcard version 35.8.1 contains malicious code that, upon being required, downloads and executes an opaque binary from obfuscated Cloudflare Workers hosts. This binary is saved to a temporary directory, given executable permissions, and run detached from the main process. The package disguises this behavior by using runtime string concatenation to evade static detection and mimics a Sentry-style APM SDK, which is unrelated to its stated UI-input-card functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dolyame-ui-inputcard npm package version 35.8.1 includes malicious code in _shim.js and lib/telemetry.js that selects a platform-specific asset and fetches an opaque binary from one of three obfuscated Cloudflare Workers hosts with a DNS-TXT chunked-base64 fallback via *.dl.wel1.ru. This binary is written to a temporary file path (/var/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe), permissions are set to executable (chmod 0755), and it is spawned detached via shell commands (/bin/sh -c or cmd). The package uses runtime string operations to construct endpoint hostnames and Node.js API names to evade static scanners. This behavior is unrelated to the package's declared purpose as a UI input card component.
Potential Impact
This malicious behavior allows the package to execute arbitrary code on the host system without user consent or verification, potentially leading to system compromise or unauthorized actions. The lack of hash or signature verification for the downloaded binary increases risk. However, there are no known exploits in the wild reported at this time.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using version 35.8.1 of dolyame-ui-inputcard. Remove this package from projects and replace it with a trusted alternative. Monitor vendor advisories and npm security notices for updates or official fixes. Since this is not a cloud service, remediation depends on user action.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13575
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75f711bf8831d53984fb96
Added to database: 08/07/2026, 15:17:37 UTC
Last enriched: 08/07/2026, 15:43:05 UTC
Last updated: 08/07/2026, 15:43:05 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.