{"id":"MAL-2026-12546","summary":"Malicious code in checkout-cashback-logic (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (493f562fef163499ed128f94b588b857aa8016e563a6291459cfe79f0c8571b3)\ncheckout-cashback-logic@35.4.3 silently requires _bootstrap.js when the package is loaded. The bootstrap script assembles Cloudflare Workers subdomains (oob-worker.cf*.workers.dev) from split string arrays, with a DNS TXT chunked fallback channel using *.dl.wel1.ru subdomains reconstructed the same way. It downloads a platform-specific native executable, writes it to /tmp under hidden or misleading names (a dotfile such as.cache_\u003chex\u003e/.analytics_state on POSIX, dotnet_diag_\u003chex\u003e.exe on Windows), chmods it 0755, and spawns it detached via /bin/sh or cmd. There is no integrity check on the fetched binary, the destinations are unrelated to the package's stated logging/cashback purpose, and the string-splitting reconstruction of the hosts is deliberate evasion of static analysis. Any require() of this package results in an opaque attacker-controlled binary running on the installer's host.\n","modified":"2026-08-05T14:35:10.656794284Z","published":"2026-08-05T14:15:48Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:14.969856455Z","modified_time":"2026-08-05T14:15:48Z","sha256":"493f562fef163499ed128f94b588b857aa8016e563a6291459cfe79f0c8571b3","source":"amazon-inspector","versions":["35.4.3"],"id":"IN-MAL-2026-015230"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-cashback-logic/v/35.4.3"}],"affected":[{"package":{"name":"checkout-cashback-logic","ecosystem":"npm","purl":"pkg:npm/checkout-cashback-logic"},"versions":["35.4.3"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"checkout-cashback-logic-35.4.3.tgz","hashes":{"sha512_sri":"sha512-8q6ftGi/dFB1qRnRnEpCZNM1NsuKRoBJJQpvIQ5qMJS2DtbqULw45tiaFRpb5BnJCuo+bTAc2TlVlLhno+jsPQ==","sha1":"7bc2edccbf5ac2398b361f626846cf6d6ed25dc2"}}],"evidence_files":[{"sha256":"5a7946084b97c9ab756beb94f79b0bc6c6fd53e47b930c8eabf6a0e14fc9bc21","tlsh":"a5b198aa156a70184b70d7e4c6175415f566f2637380c294f79ca9d81ff722482b2efc","path":"_bootstrap.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-cashback-logic/MAL-2026-12546.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}