{"id":"MAL-2026-12580","summary":"Malicious code in checkout-mobile-total (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c1943ab64ce84576c6fef87d3b46187d0e442941f691d645adfe5f73595cfe9a)\nOn require of the package, index.js unconditionally loads _vendor.js, which fetches a platform-specific binary from hardcoded Cloudflare Workers hosts (e.g. oob-worker.cf100-416.workers.dev) assembled by joining split string fragments, with a DNS-TXT covert-channel fallback to *.dl.wel1.ru. The retrieved payload is written to /var/tmp or %TEMP% under disguised names (.cache_\u003crnd\u003e, dotnet_diag_\u003crnd\u003e.exe), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed, hostnames are unrelated to any declared publisher, and the destinations are concealed via string-split obfuscation. Package name mimics a checkout/payments library, consistent with typosquat lure targeting mobile checkout tooling.\n","modified":"2026-08-05T14:35:33.524131815Z","published":"2026-08-05T14:10:03Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.8.9"],"id":"IN-MAL-2026-015192","import_time":"2026-08-05T14:20:11.515220185Z","modified_time":"2026-08-05T14:10:03Z","sha256":"c1943ab64ce84576c6fef87d3b46187d0e442941f691d645adfe5f73595cfe9a"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-mobile-total/v/35.8.9"}],"affected":[{"package":{"name":"checkout-mobile-total","ecosystem":"npm","purl":"pkg:npm/checkout-mobile-total"},"versions":["35.8.9"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-mobile-total/MAL-2026-12580.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"checkout-mobile-total-35.8.9.tgz","hashes":{"sha1":"af05d234bcac4965d37cc6ffc0783ff1da5740e0","sha512_sri":"sha512-ybtB6SI7++dMu8LohvMcoqXwMm1/2HwYb7MQUdqza37Qsvl94OcvnFeLrOXz4GLplwFiBxV8D/0AQDqQceBAxg=="}}],"evidence_files":[{"tlsh":"7eb1975a15aa70188bb0d7e0c717541af65bf6633780c6d8f79c95981f7212483b2efc","path":"_vendor.js","sha256":"5005289cb1967d2e83a25d56239d58ebfce164a1b80e8c8f6e8204f6cfddc7cc"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}