{"id":"MAL-2026-12542","summary":"Malicious code in checkout-accounts-logic (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (005b3edb78076f5105de32feda80276d41059215378d6ab90f2d11a332685c6a)\nOn require(), the package loads _adapter.js which reconstructs C2 hostnames from split string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, and *.dl.wel1.ru assembled from ['sdk.d','l.','wel1','.r','u']), fetches a platform-specific binary via https.get, writes it to a temp path with a disguised name (dotnet_diag_*.exe,.cache_*), chmods it 0o755, and detached-spawns it via /bin/sh -c or cmd.exe /c. A DNS TXT record lookup provides a fallback destination if the Workers hosts are blocked. stderr is stubbed to suppress logging. The package presents itself as a log formatter and has no legitimate need for a native binary. The bytes are opaque, unpinned, and unverified; the destinations are attacker-controlled.\n","modified":"2026-08-05T14:35:08.847566365Z","published":"2026-08-05T14:15:41Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:15:41Z","sha256":"005b3edb78076f5105de32feda80276d41059215378d6ab90f2d11a332685c6a","source":"amazon-inspector","versions":["35.9.2"],"id":"IN-MAL-2026-015229","import_time":"2026-08-05T14:20:14.892032984Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-accounts-logic/v/35.9.2"}],"affected":[{"package":{"name":"checkout-accounts-logic","ecosystem":"npm","purl":"pkg:npm/checkout-accounts-logic"},"versions":["35.9.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"3ca1969616aa70098bb09be4c7175415f56ae2633381c2d8f75ca5941fb312483b2dfc","path":"_adapter.js","sha256":"1b66cc3b6ecae3ab09116f9ebb438b61feb4db084b37b32f777d2a205e8156dc"}],"package_integrity":[{"filename":"checkout-accounts-logic-35.9.2.tgz","hashes":{"sha1":"a47d74ef3f1c605fc2793e8da1c9aeb677228789","sha512_sri":"sha512-nZBv6jgSeYUbZioryuHMFA0LiJ2LidIYX71OCt9yaPgEZPQF5Bpgc6IFsesGbJ7tRuNj6k4VhHUq8L+w9UmynQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-accounts-logic/MAL-2026-12542.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}