{"id":"MAL-2026-12584","summary":"Malicious code in checkout-pay-button-logic (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9d4bf54bc4e3750c7e9bc6ef385108c37ee00b486858c0576585ef2f88780385)\nOn require, index.js invokes _helpers.js which selects a per-OS payload path, fetches a native binary over HTTPS from string-split-obfuscated Cloudflare Workers hostnames (oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT base64 fallback via sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes it to /tmp/.cache_\u003chex\u003e or %TEMP%\\dotnet_diag_\u003chex\u003e.exe, chmods 0755, and detached-spawns it via /bin/sh -c or cmd.exe /c start /b. Destination hostnames and fallback resolvers are assembled by joining split string fragments to evade static scanners, and the dropped file uses cover-story names (analytics_state, dotnet_diag). Reads DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK to mimic a legitimate telemetry opt-out. Behavior is unrelated to the package's stated purpose.\n","modified":"2026-08-05T14:35:36.003982080Z","published":"2026-08-05T14:10:14Z","database_specific":{"malicious-packages-origins":[{"sha256":"9d4bf54bc4e3750c7e9bc6ef385108c37ee00b486858c0576585ef2f88780385","source":"amazon-inspector","versions":["35.3.8"],"id":"IN-MAL-2026-015193","import_time":"2026-08-05T14:20:11.62831894Z","modified_time":"2026-08-05T14:10:14Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-pay-button-logic/v/35.3.8"}],"affected":[{"package":{"name":"checkout-pay-button-logic","ecosystem":"npm","purl":"pkg:npm/checkout-pay-button-logic"},"versions":["35.3.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"c101e4dd9cfc5c0089a85620549d2e2849c063065e17074acefbd0e94eeb60ce","tlsh":"cda1a76a067ab0188b70dbe5c7175415f66bf663368081c4f75c99980f761348372efc"}],"package_integrity":[{"filename":"checkout-pay-button-logic-35.3.8.tgz","hashes":{"sha1":"3fc4b55feeba9456d00362e5a54abcf907484129","sha512_sri":"sha512-wul+WjEoM9i9Q6DCpHEGvCXaVPluEasee9uiFycxh7CN0aJaHCgybPUHIM8Tsb/JgSDcL2IVCVtLjOqqzJuKnw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-pay-button-logic/MAL-2026-12584.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}