{"id":"MAL-2026-12571","summary":"Malicious code in checkout-mobile-accounts-old (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (67f6eeca2bb17729fe666aaaf6849e26c474a130f5a17ca7dfe6c4c6c6ae4e8a)\nOn require() of checkout-mobile-accounts-old, index.js loads _support.js which downloads a platform-specific native binary from hardcoded Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS-TXT covert-channel fallback under wel1.ru (sdk./ext./pkg./net.dl.wel1.ru), stages the payload under /var/tmp or %TEMP% with disguised filenames (dotnet_diag_*.exe,.cache_*), chmods 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd. The C2 hostnames are assembled at runtime by joining split string literals, and the DNS fallback reassembles a base64-encoded binary from numbered TXT records (c.\u003cdomain\u003e for chunk count, 0..n.\u003cdomain\u003e for chunks). Environment variables DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, and DO_NOT_TRACK, plus a cooldown flag file, are checked to suppress the fetch. The delivery, obfuscation, disguised staging path, detached execution, and DNS-TXT fallback channel are all unrelated to the package's stated device-integration purpose and constitute full-host remote code execution against any installer that requires the package.\n","modified":"2026-08-05T14:35:29.259279226Z","published":"2026-08-05T14:10:29Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015194","import_time":"2026-08-05T14:20:11.710390653Z","modified_time":"2026-08-05T14:10:29Z","sha256":"67f6eeca2bb17729fe666aaaf6849e26c474a130f5a17ca7dfe6c4c6c6ae4e8a","source":"amazon-inspector","versions":["35.6.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-mobile-accounts-old/v/35.6.6"}],"affected":[{"package":{"name":"checkout-mobile-accounts-old","ecosystem":"npm","purl":"pkg:npm/checkout-mobile-accounts-old"},"versions":["35.6.6"],"database_specific":{"indicators":{"package_integrity":[{"filename":"checkout-mobile-accounts-old-35.6.6.tgz","hashes":{"sha1":"ae5e6ac38700c7bbb3dbe727e86cda5d8546db15","sha512_sri":"sha512-/Ts6hSnaQRDiOoxhqBvQGnpmBl9dHkBpBsYegAyYIVUuwfXAbWQjmoJh12ioY1bRZiQmQdQ5uLWlX6vQF3CiUw=="}}],"evidence_files":[{"path":"_support.js","sha256":"35d5def3672af7c393a8c1cf3c3b29761bc3138889d199ce38e39efb87dd5709","tlsh":"0ba1a55a16a670188bb09be597175416f65bf66333c0c2c8fb5ca5981f7322483b2efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-mobile-accounts-old/MAL-2026-12571.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}