Malicious code in dolyame-ui-sortablelist (npm)
The npm package dolyame-ui-sortablelist version 35.8.1 contains malicious code that, upon being imported, fetches and executes a platform-specific attacker-controlled binary. This binary is retrieved from obfuscated Cloudflare Workers hosts or reconstructed from DNS TXT records, then written to a temporary file disguised as system diagnostics output and executed detached from the main process. The package attempts to evade detection by obfuscating imports and gating execution behind environment variables related to telemetry opt-out, but the actual behavior is unauthorized remote code execution at import time.
AI Analysis
Technical Summary
The dolyame-ui-sortablelist npm package version 35.8.1 includes malicious functionality that triggers on require(). It fetches a platform-specific executable from obfuscated Cloudflare Workers domains or reconstructs it from DNS TXT records hosted under several 'dl.wel1.ru' subdomains. The binary is saved to a temporary file with a name resembling OS diagnostic files, permissions are set to executable, and it is spawned detached via a shell command. This drop-and-execute logic is redundantly implemented in multiple package files to ensure execution. The package uses string concatenation and bracket notation to evade static detection of 'child_process' and 'fs.chmodSync'. It masquerades as telemetry/analytics software and uses environment variables related to telemetry opt-out as a cover to conceal its malicious behavior. This results in silent execution of attacker-controlled code on the host system at import time.
Potential Impact
This malicious package enables remote code execution on the host system at the time the package is imported, allowing an attacker to run arbitrary code with the privileges of the importing process. The execution is stealthy, using obfuscated network hosts and disguising the binary as system diagnostics files. This can lead to full system compromise, data theft, or further malware deployment. There are no known exploits in the wild reported yet.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fixed version or official guidance is available, avoid using version 35.8.1 of dolyame-ui-sortablelist. Remove the package from your environment if already installed. Monitor for updates from the package maintainers or npm security advisories for remediation. Consider scanning your environment for the presence of this package and any suspicious binaries matching the described patterns.
Malicious code in dolyame-ui-sortablelist (npm)
Description
The npm package dolyame-ui-sortablelist version 35.8.1 contains malicious code that, upon being imported, fetches and executes a platform-specific attacker-controlled binary. This binary is retrieved from obfuscated Cloudflare Workers hosts or reconstructed from DNS TXT records, then written to a temporary file disguised as system diagnostics output and executed detached from the main process. The package attempts to evade detection by obfuscating imports and gating execution behind environment variables related to telemetry opt-out, but the actual behavior is unauthorized remote code execution at import time.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dolyame-ui-sortablelist npm package version 35.8.1 includes malicious functionality that triggers on require(). It fetches a platform-specific executable from obfuscated Cloudflare Workers domains or reconstructs it from DNS TXT records hosted under several 'dl.wel1.ru' subdomains. The binary is saved to a temporary file with a name resembling OS diagnostic files, permissions are set to executable, and it is spawned detached via a shell command. This drop-and-execute logic is redundantly implemented in multiple package files to ensure execution. The package uses string concatenation and bracket notation to evade static detection of 'child_process' and 'fs.chmodSync'. It masquerades as telemetry/analytics software and uses environment variables related to telemetry opt-out as a cover to conceal its malicious behavior. This results in silent execution of attacker-controlled code on the host system at import time.
Potential Impact
This malicious package enables remote code execution on the host system at the time the package is imported, allowing an attacker to run arbitrary code with the privileges of the importing process. The execution is stealthy, using obfuscated network hosts and disguising the binary as system diagnostics files. This can lead to full system compromise, data theft, or further malware deployment. There are no known exploits in the wild reported yet.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fixed version or official guidance is available, avoid using version 35.8.1 of dolyame-ui-sortablelist. Remove the package from your environment if already installed. Monitor for updates from the package maintainers or npm security advisories for remediation. Consider scanning your environment for the presence of this package and any suspicious binaries matching the described patterns.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13599
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a75f70fbf8831d53984fa13
Added to database: 08/07/2026, 15:17:35 UTC
Last enriched: 08/07/2026, 15:33:36 UTC
Last updated: 09/21/2026, 23:49:21 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.