{"id":"MAL-2026-12579","summary":"Malicious code in checkout-mobile-promocode (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f8b1a15a2100e63737bf9fdc85ec750761a4e58b07f961d8a5734a6f99626026)\nOn require, index.js loads _vendor.js which reconstructs destination hostnames from split string literals (e.g. [\"oob-worker.c\",\"f102-baf.worker\",\"s.dev\"].join(\"\") and ['sdk.d','l.w','el1.ru'].join(\"\")) to hide them from static inspection. It selects a platform-specific asset, downloads an unpinned, unverified executable from one of several *.workers.dev endpoints, falling back to DNS TXT base64 chunks under *.dl.wel1.ru (sdk/ext/pkg/net.dl.wel1.ru), writes it to /var/tmp or %TEMP% under a disguised name such as dotnet_diag_*.exe or.cache_*, sets mode 0755 via fs.chmodSync, and spawns it detached via cp.spawn(\"/bin/sh\",[\"-c\", fp+\" &\"], {detached:true}) or cmd.exe. A sibling file lib/telemetry.js contains a structurally identical fetch-decode-chmod-spawn payload using require(\"child_\"+\"process\") and fs[\"chmod\"+\"Sync\"], packaged as an \"analytics SDK\" variant of the same dropper. The package name mimics a legitimate mobile-checkout/promo-code component but its only on-import effect is delivery and execution of attacker-controlled native code.\n","modified":"2026-08-05T14:35:33.197741847Z","published":"2026-08-05T14:10:52Z","database_specific":{"malicious-packages-origins":[{"sha256":"f8b1a15a2100e63737bf9fdc85ec750761a4e58b07f961d8a5734a6f99626026","source":"amazon-inspector","versions":["35.6.9"],"id":"IN-MAL-2026-015197","import_time":"2026-08-05T14:20:11.983357403Z","modified_time":"2026-08-05T14:10:52Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-mobile-promocode/v/35.6.9"}],"affected":[{"package":{"name":"checkout-mobile-promocode","ecosystem":"npm","purl":"pkg:npm/checkout-mobile-promocode"},"versions":["35.6.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"9a392d4eafb4ae9d81c226cfcb8f91d6cd564e04eb3fd390b774eb56b12d41bb","tlsh":"8ca1a5aa156670194bb0d7e486075406f65bf6637380c5d8fb9ca9980fb222483b2efc"},{"sha256":"45a0d57a7f9d2c590f80b30bcf1a15ca52ec14d1e24bd3d843d57ec942bef0bc","tlsh":"cf835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}],"package_integrity":[{"filename":"checkout-mobile-promocode-35.6.9.tgz","hashes":{"sha512_sri":"sha512-Ph2MxHhqHyB2AAxDKhIIqrb8yoaRap3zsy9nRqFoOxdHuuvXzOd/wa+i8xpzd2Ygx9+JmYONyuHqx3oQdVCn2A==","sha1":"28dbbada9d06d45338e275d58791e0ba905a53a4"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-mobile-promocode/MAL-2026-12579.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}