Malicious code in dolyame-ui-mediainfohoc (npm)
The npm package dolyame-ui-mediainfohoc contains malicious code that downloads and executes opaque binaries from hardcoded remote hosts. It writes these binaries to temporary directories, sets executable permissions, and spawns them detached from the main process. The package uses obfuscation techniques to evade detection and disguises this behavior as telemetry. Two independent backdoor droppers are embedded, one in _platform.js and another in lib/telemetry.js, both capable of executing the payload upon requiring the package. The package name mimics a legitimate UI helper but is in fact a malicious package.
AI Analysis
Technical Summary
The npm package dolyame-ui-mediainfohoc version 35.8.1 includes embedded malicious code that, upon being required, selects a platform-specific asset and downloads an opaque binary from three hardcoded Cloudflare Workers domains with DNS-TXT fallback via *.dl.wel1.ru subdomains. The binary is written to a temporary directory under a hidden or executable name, permissions are set to executable (chmod 0755), and it is spawned detached using shell commands. The code uses string concatenation and array joins to evade static detection and falsely labels this behavior as telemetry. A duplicate dropper is embedded in lib/telemetry.js, wrapped in a fake analytics SDK, which decodes a base64 buffer, writes it to disk, sets permissions, and executes it similarly. Both droppers are independent and shipped within the same package, enabling remote code execution when the package is imported.
Potential Impact
This malicious package enables remote code execution on any system that installs and requires dolyame-ui-mediainfohoc version 35.8.1. The dropped binaries are opaque and fetched from attacker-controlled infrastructure, potentially allowing arbitrary code execution, persistence, and further compromise of the host system. The obfuscation and dual dropper design increase the difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should immediately remove dolyame-ui-mediainfohoc version 35.8.1 from their projects and dependency trees. Avoid installing or requiring this package. Use trusted sources and verify package integrity before installation. Monitor for any unexpected network connections to the indicated domains and scan systems for dropped binaries in temporary directories. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in dolyame-ui-mediainfohoc (npm)
Description
The npm package dolyame-ui-mediainfohoc contains malicious code that downloads and executes opaque binaries from hardcoded remote hosts. It writes these binaries to temporary directories, sets executable permissions, and spawns them detached from the main process. The package uses obfuscation techniques to evade detection and disguises this behavior as telemetry. Two independent backdoor droppers are embedded, one in _platform.js and another in lib/telemetry.js, both capable of executing the payload upon requiring the package. The package name mimics a legitimate UI helper but is in fact a malicious package.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package dolyame-ui-mediainfohoc version 35.8.1 includes embedded malicious code that, upon being required, selects a platform-specific asset and downloads an opaque binary from three hardcoded Cloudflare Workers domains with DNS-TXT fallback via *.dl.wel1.ru subdomains. The binary is written to a temporary directory under a hidden or executable name, permissions are set to executable (chmod 0755), and it is spawned detached using shell commands. The code uses string concatenation and array joins to evade static detection and falsely labels this behavior as telemetry. A duplicate dropper is embedded in lib/telemetry.js, wrapped in a fake analytics SDK, which decodes a base64 buffer, writes it to disk, sets permissions, and executes it similarly. Both droppers are independent and shipped within the same package, enabling remote code execution when the package is imported.
Potential Impact
This malicious package enables remote code execution on any system that installs and requires dolyame-ui-mediainfohoc version 35.8.1. The dropped binaries are opaque and fetched from attacker-controlled infrastructure, potentially allowing arbitrary code execution, persistence, and further compromise of the host system. The obfuscation and dual dropper design increase the difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should immediately remove dolyame-ui-mediainfohoc version 35.8.1 from their projects and dependency trees. Avoid installing or requiring this package. Use trusted sources and verify package integrity before installation. Monitor for any unexpected network connections to the indicated domains and scan systems for dropped binaries in temporary directories. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13588
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a75f710bf8831d53984fa8f
Added to database: 08/07/2026, 15:17:36 UTC
Last enriched: 08/07/2026, 15:35:48 UTC
Last updated: 09/22/2026, 00:07:43 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.