{"id":"MAL-2026-12559","summary":"Malicious code in checkout-desktop-pay-widget (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6d9f6914ba98b5cf6aa04dd51fb0ef5a1f454a0cb87409ea43482afd6b99b38d)\nOn require('checkout-desktop-pay-widget'), index.js loads _shim.js which selects a platform-specific asset, downloads an opaque native binary from one of four runtime-assembled Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev / cf100-416.workers.dev variants), writes it to /tmp or %TEMP% under decoy names (.cache_\u003chex\u003e on POSIX, dotnet_diag_\u003chex\u003e.exe on Windows), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe. Destination hostnames are split into fragments and joined at runtime to evade static string scanning. A DNS-TXT fallback channel resolves TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, concatenates chunks, base64-decodes the result to executable bytes, and runs them — a covert payload-retrieval channel that bypasses HTTP egress controls. No signature or hash verification is performed. Function names (bootstrap/telemetry, DISABLE_TELEMETRY,.analytics_state lock file) present a benign cover story that conflicts with the fetch-write-chmod-exec chain. Package name mimics a checkout/payment widget but the shipped code implements a full-host remote code execution dropper.\n","modified":"2026-08-05T14:35:23.258793858Z","published":"2026-08-05T14:12:55Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.6.3"],"id":"IN-MAL-2026-015211","import_time":"2026-08-05T14:20:13.25726382Z","modified_time":"2026-08-05T14:12:55Z","sha256":"6d9f6914ba98b5cf6aa04dd51fb0ef5a1f454a0cb87409ea43482afd6b99b38d"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-desktop-pay-widget/v/35.6.3"}],"affected":[{"package":{"name":"checkout-desktop-pay-widget","ecosystem":"npm","purl":"pkg:npm/checkout-desktop-pay-widget"},"versions":["35.6.3"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"a7b1a69a167a70188bb0a7e4c71b4415f66bf66337808294f79ca5985f72124c3b2ffc","path":"_shim.js","sha256":"a8bc2c59f6ecd92ff19654b6f97b6b68130c4f02b0266dcf4db906720ecf9a33"}],"package_integrity":[{"filename":"checkout-desktop-pay-widget-35.6.3.tgz","hashes":{"sha1":"5aed91c8d466fbc42e262e1ddecff8fd41fccf87","sha512_sri":"sha512-Jrt7Fcu3NYPl+y9DCR8iT+hZ4o01N70hWzwPfYJVdiU8keM44fucOLRn7HmjTHIbZ2Vkw5ITSZ7vJgw+qSfSLw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-desktop-pay-widget/MAL-2026-12559.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}