Malicious code in dolyame-ui-inputcount (npm)
The npm package dolyame-ui-inputcount version 35.8.1 contains malicious code that, upon being required, downloads and executes a platform-specific binary from obfuscated Cloudflare Worker endpoints. The package uses string fragment assembly and other obfuscation techniques to evade detection. It writes the binary to temporary directories with executable permissions and spawns it detached from the main process. The package masquerades as an analytics or observability SDK but has no legitimate reason to fetch and run opaque binaries at import time.
AI Analysis
Technical Summary
The dolyame-ui-inputcount npm package version 35.8.1 includes malicious code in its _helpers.js and lib/telemetry.js files. When the package is imported, it detects the host OS and architecture, then downloads a platform-specific binary from one of several obfuscated Cloudflare Worker endpoints, with DNS TXT record fallback to suspicious domains. The binary is saved to a temporary location with executable permissions and executed in a detached shell process. The code uses string concatenation to hide suspicious calls such as require('child_process') and fs.chmodSync, and includes a marker file to prevent repeated execution. The package name mimics a legitimate UI component library but performs unauthorized remote code execution at import time.
Potential Impact
This malicious package enables remote code execution on the host system by downloading and running an unauthorized binary. This can lead to full system compromise, data theft, persistence, and further malicious activity. The obfuscation and use of anonymous Cloudflare Worker infrastructure complicate detection and attribution. There is no indication of active exploitation in the wild yet, but the presence of such code in a widely used package repository poses a significant risk to developers and production environments that depend on this package.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove version 35.8.1 of dolyame-ui-inputcount from their dependencies and avoid installing or importing this package. Audit existing environments for the presence of the package and any dropped binaries in temporary directories. Consider using package integrity verification and supply chain security tools to prevent installation of malicious packages. Monitor vendor advisories and trusted security sources for updates or official fixes.
Malicious code in dolyame-ui-inputcount (npm)
Description
The npm package dolyame-ui-inputcount version 35.8.1 contains malicious code that, upon being required, downloads and executes a platform-specific binary from obfuscated Cloudflare Worker endpoints. The package uses string fragment assembly and other obfuscation techniques to evade detection. It writes the binary to temporary directories with executable permissions and spawns it detached from the main process. The package masquerades as an analytics or observability SDK but has no legitimate reason to fetch and run opaque binaries at import time.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dolyame-ui-inputcount npm package version 35.8.1 includes malicious code in its _helpers.js and lib/telemetry.js files. When the package is imported, it detects the host OS and architecture, then downloads a platform-specific binary from one of several obfuscated Cloudflare Worker endpoints, with DNS TXT record fallback to suspicious domains. The binary is saved to a temporary location with executable permissions and executed in a detached shell process. The code uses string concatenation to hide suspicious calls such as require('child_process') and fs.chmodSync, and includes a marker file to prevent repeated execution. The package name mimics a legitimate UI component library but performs unauthorized remote code execution at import time.
Potential Impact
This malicious package enables remote code execution on the host system by downloading and running an unauthorized binary. This can lead to full system compromise, data theft, persistence, and further malicious activity. The obfuscation and use of anonymous Cloudflare Worker infrastructure complicate detection and attribution. There is no indication of active exploitation in the wild yet, but the presence of such code in a widely used package repository poses a significant risk to developers and production environments that depend on this package.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove version 35.8.1 of dolyame-ui-inputcount from their dependencies and avoid installing or importing this package. Audit existing environments for the presence of the package and any dropped binaries in temporary directories. Consider using package integrity verification and supply chain security tools to prevent installation of malicious packages. Monitor vendor advisories and trusted security sources for updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13576
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75f70cbf8831d53984ee8e
Added to database: 08/07/2026, 15:17:32 UTC
Last enriched: 08/07/2026, 15:26:53 UTC
Last updated: 08/07/2026, 15:26:53 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.