{"id":"MAL-2026-12578","summary":"Malicious code in checkout-mobile-pay-widget (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (57c8ea8352e1550f445ade3ea180ed272af5e77663f68d6d65ca9c90891d451f)\ncheckout-mobile-pay-widget@35.9.1 is a dropper disguised as a mobile-payment/native-bridge SDK. On require() of the package, index.js unconditionally loads _adapter.js, which at module load selects a platform-specific payload, downloads it from one of four Cloudflare Workers mirrors whose hostnames are reconstructed at runtime via array-join splits (e.g. [\"oob-worker.cf101-adf.worke\",\"rs.dev\"].join(\"\")), with a DNS-TXT chunked base64 covert channel over *.dl.wel1.ru as fallback. The downloaded bytes are written to /tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows — cover-story names impersonating benign runtime artifacts — chmod'd 0755, and spawned detached via /bin/sh -c \"\u003cpath\u003e &\" or cmd /c start /b. A stamp file /tmp/.analytics_state gates re-execution (EXPIRE_SEC=22056), stderr is stubbed to no-ops, and DISABLE_TELEMETRY-style env vars are honored to appear inert in sandboxes. No hash or signature verification is performed; the fetched bytes are attacker-controlled. The package advertises a native mobile-pay bridge but ships no such functionality — the only effect of installing/requiring it is the drop-and-exec chain.\n","modified":"2026-08-05T14:35:33.168009579Z","published":"2026-08-05T14:09:55Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T14:09:55Z","sha256":"57c8ea8352e1550f445ade3ea180ed272af5e77663f68d6d65ca9c90891d451f","source":"amazon-inspector","versions":["35.9.1"],"id":"IN-MAL-2026-015191","import_time":"2026-08-05T14:20:11.424721524Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-mobile-pay-widget/v/35.9.1"}],"affected":[{"package":{"name":"checkout-mobile-pay-widget","ecosystem":"npm","purl":"pkg:npm/checkout-mobile-pay-widget"},"versions":["35.9.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-mobile-pay-widget/MAL-2026-12578.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"checkout-mobile-pay-widget-35.9.1.tgz","hashes":{"sha1":"1df6ec5decec1a0a7ec01cde9c2f8d96fea262f6","sha512_sri":"sha512-/ZrePqeU7Z2bAevGiXrT8d5VES/1EWL/OwQKAf57xnsdA4B5g6wUeoavNDk60CyxX6hS4d9MXMwdKwRlC1yhjA=="}}],"evidence_files":[{"path":"_adapter.js","sha256":"aff314fe4bbde3a89ac6aa65e740fc14c639e219c90bfe6f1b4921b66f0bc488","tlsh":"48b1b69616a630198bb097e4c7174416f65be2633381d288fb9c99985fb3524c3b2efc"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}