Malicious code in dolyame-ui-storybook-menu (npm)
The npm package dolyame-ui-storybook-menu version 35.5.6 contains malicious code that downloads and executes a remote binary upon being required. It masquerades as telemetry functionality but actually fetches a platform-specific executable from obfuscated Cloudflare Worker endpoints, writes it to disk with disguised filenames, sets execution permissions, and runs it detached. This behavior results in full remote code execution on any system importing the package.
AI Analysis
Technical Summary
The package's main entry point unconditionally loads a module that dynamically reconstructs Cloudflare Worker hostnames at runtime to fetch an opaque binary payload. This payload is saved to a temporary file disguised as a system-related filename, permissions are set to executable, and the binary is spawned detached using platform-specific shell commands. The package includes a telemetry-like gating mechanism that does not prevent the malicious payload execution. This constitutes a remote code execution dropper triggered simply by requiring the package, affecting version 35.5.6.
Potential Impact
Any system that installs and imports dolyame-ui-storybook-menu version 35.5.6 is at risk of arbitrary remote code execution due to the automatic download and execution of a malicious binary. This can lead to full compromise of the host environment without user interaction beyond package installation or import.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or importing version 35.5.6 of dolyame-ui-storybook-menu. Remove the package from existing environments and monitor for any unauthorized execution of binaries resembling the described behavior. Check vendor or repository advisories for updates or official fixes.
Malicious code in dolyame-ui-storybook-menu (npm)
Description
The npm package dolyame-ui-storybook-menu version 35.5.6 contains malicious code that downloads and executes a remote binary upon being required. It masquerades as telemetry functionality but actually fetches a platform-specific executable from obfuscated Cloudflare Worker endpoints, writes it to disk with disguised filenames, sets execution permissions, and runs it detached. This behavior results in full remote code execution on any system importing the package.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The package's main entry point unconditionally loads a module that dynamically reconstructs Cloudflare Worker hostnames at runtime to fetch an opaque binary payload. This payload is saved to a temporary file disguised as a system-related filename, permissions are set to executable, and the binary is spawned detached using platform-specific shell commands. The package includes a telemetry-like gating mechanism that does not prevent the malicious payload execution. This constitutes a remote code execution dropper triggered simply by requiring the package, affecting version 35.5.6.
Potential Impact
Any system that installs and imports dolyame-ui-storybook-menu version 35.5.6 is at risk of arbitrary remote code execution due to the automatic download and execution of a malicious binary. This can lead to full compromise of the host environment without user interaction beyond package installation or import.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or importing version 35.5.6 of dolyame-ui-storybook-menu. Remove the package from existing environments and monitor for any unauthorized execution of binaries resembling the described behavior. Check vendor or repository advisories for updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13186
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738535bf8831d5394f0aca
Added to database: 08/05/2026, 18:47:17 UTC
Last enriched: 08/05/2026, 19:15:58 UTC
Last updated: 08/05/2026, 20:10:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.