{"id":"MAL-2026-12576","summary":"Malicious code in checkout-mobile-input-email (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f9c13bf58568e58ecec010552f23cd8eb27cef188f4ed0c905e832fa0f8d0372)\nOn require('checkout-mobile-input-email'), index.js loads _helpers.js which assembles hostnames via string-array.join(\"\") (e.g. [\"oob-worker.cf103-070.workers.\",\"dev\"].join(\"\"), [\"oob-\",\"worker.cf102-baf.workers.d\",\"ev\"].join(\"\"), and ['sdk.dl.wel1.','ru'].join(\"\")) to reach oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, and DNS-TXT fallback resolvers under *.dl.wel1.ru. A platform-specific binary is downloaded, written to /tmp or %TEMP% under disguised names (.cache_\u003chex\u003e,.analytics_state, dotnet_diag_\u003chex\u003e.exe), chmod'd 0755, and spawned detached via spawn(\"/bin/sh\",...) with fp+' &' or via cmd.exe /c start /b at _helpers.js line 121-139. Destination hostnames are anonymous Cloudflare Workers subdomains unrelated to any legitimate 'checkout mobile input email' functionality; the base64/DNS-TXT fallback resolver path constitutes a secondary exfil/download channel. A large sibling bundle lib/telemetry.js (~81 KB) ships in the tarball but is not require()'d from the traced modules; the executed native binary may reference or replace it.\n","modified":"2026-08-05T14:35:31.857368257Z","published":"2026-08-05T14:11:10Z","database_specific":{"malicious-packages-origins":[{"versions":["35.6.8"],"id":"IN-MAL-2026-015199","import_time":"2026-08-05T14:20:12.169842939Z","modified_time":"2026-08-05T14:11:10Z","sha256":"f9c13bf58568e58ecec010552f23cd8eb27cef188f4ed0c905e832fa0f8d0372","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-mobile-input-email/v/35.6.8"}],"affected":[{"package":{"name":"checkout-mobile-input-email","ecosystem":"npm","purl":"pkg:npm/checkout-mobile-input-email"},"versions":["35.6.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"358a685fad8ae74146d82edea667281de909cc794a721fbf5a87602a52e0ad60","tlsh":"4ca1955a16aa30198bb0d7e4c7274416f65ee6a33780c2c8fb9ca5945f72524c3b2dfc"},{"sha256":"becf8c44324f8b012efd2c518d31fff20312fbbd13865b5362f7c18971d7cff3","tlsh":"28835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"hashes":{"sha1":"03b1a97921d64c2bbd26e1f1d63cb57f743f5909","sha512_sri":"sha512-vbLIe1VAQs7oVeHHNrGleXPRIk7h3zRgAumTf6lqvmcNsS/8u12iBR1cmu9Dqox0W5DZPIy8G1cLr+eOdiiFGw=="},"filename":"checkout-mobile-input-email-35.6.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-mobile-input-email/MAL-2026-12576.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}