{"id":"MAL-2026-12557","summary":"Malicious code in checkout-desktop-legal (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9e7a07623c75a85bada6117a7a71f40d19924be192a769534e544ffe31f036b0)\nOn require() of checkout-desktop-legal, index.js loads _compat.js, which selects a platform-specific asset path and downloads a binary from Cloudflare Workers hosts whose names are assembled at runtime via array/join concatenation (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS TXT fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The retrieved bytes are written to a temp path under a disguise name (.cache_\u003chex\u003e on Unix, dotnet_diag_\u003chex\u003e.exe on Windows), fs.chmodSync sets mode 0755, and the file is spawned detached via /bin/sh -c \"\u003cpath\u003e &\" or cmd.exe /c start /b \u003cpath\u003e. A TTL flag file (analytics_state) throttles re-execution to roughly every six hours. A second dropper implementation with the same primitives (base64-decoded payload written to disk, chmod 0755 via string-concatenated method name, detached /bin/sh spawn) is shipped in lib/telemetry.js. The require key for child_process is itself built by string concatenation (require(\"child_\" + \"process\")), and destination hosts are split across array elements, both consistent with deliberate evasion of static URL and API detection.\n","modified":"2026-08-05T14:35:22.690928972Z","published":"2026-08-05T14:13:35Z","database_specific":{"malicious-packages-origins":[{"versions":["35.2.8"],"id":"IN-MAL-2026-015216","import_time":"2026-08-05T14:20:13.65577405Z","modified_time":"2026-08-05T14:13:35Z","sha256":"9e7a07623c75a85bada6117a7a71f40d19924be192a769534e544ffe31f036b0","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-desktop-legal/v/35.2.8"}],"affected":[{"package":{"name":"checkout-desktop-legal","ecosystem":"npm","purl":"pkg:npm/checkout-desktop-legal"},"versions":["35.2.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"checkout-desktop-legal-35.2.8.tgz","hashes":{"sha1":"1c3d600ed631e2d9a7bc677d270033aebbc64ec1","sha512_sri":"sha512-Iz1ruqvDK4mRUmyLR3dsa+7mPK2w7xiepo1N3fPxaGZm30HaI0Ykb/ZApp7Ybfkfbo/ABIHynFH3vZavybMPpg=="}}],"evidence_files":[{"tlsh":"20a1866a166670184770d7e5ca175416f66af6637380c2c8fb9c698c1ff222482b2efc","path":"_compat.js","sha256":"48bbff69f23c8feb713b60686aca21206365fe9c6c313e175b5ab234c58337cf"},{"sha256":"70d1bd882ee0f2ea8289d131dbdaa06e6dcf2aad342cc47fdbf130a602976859","tlsh":"53835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-desktop-legal/MAL-2026-12557.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}