{"id":"MAL-2026-12593","summary":"Malicious code in checkout-storybook-default (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (844d8b490d431f2fad501a06bbcf924fe5890ba16c92157dd52488c1908f7909)\nOn require of the package, index.js loads _polyfill.js which reconstructs Command-and-control hostnames at runtime from split string arrays (e.g. oob-worker.cf10{0-3}-*.workers.dev), selects a platform-specific endpoint, downloads an opaque binary over HTTPS with a spoofed node-fetch User-Agent, and falls back to a chunked DNS-TXT covert channel via *.dl.wel1.ru hosts (e.g. sdk.dl.wel1.ru). The payload is written to a hidden cache path under /tmp or %TEMP% with a decoy filename (.cache_\u003crnd\u003e on POSIX, dotnet_diag_\u003crnd\u003e.exe on Windows), chmodded 0755, and spawned detached via /bin/sh or cmd. A marker file recording process.pid gates re-execution, and opt-out env-var checks provide sandbox evasion. The behavior has no relation to the package's stated purpose.\n","modified":"2026-08-05T14:35:40.320608071Z","published":"2026-08-05T14:08:21Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.5.1"],"id":"IN-MAL-2026-015180","import_time":"2026-08-05T14:20:10.204382477Z","modified_time":"2026-08-05T14:08:21Z","sha256":"844d8b490d431f2fad501a06bbcf924fe5890ba16c92157dd52488c1908f7909"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-storybook-default/v/35.5.1"}],"affected":[{"package":{"name":"checkout-storybook-default","ecosystem":"npm","purl":"pkg:npm/checkout-storybook-default"},"versions":["35.5.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_polyfill.js","sha256":"9de803b1e239bb7b38d15ee98ce86267fedfad10821bbffa2af82b2c1581e2d4","tlsh":"5fa1869616a670184bb0dbe4871b5415f65bf6a333c082d4fb6ca5981fb71244372efc"}],"package_integrity":[{"hashes":{"sha1":"33cd4411594b41632c7e619e229bc213de321c00","sha512_sri":"sha512-4srEQsEe9kiOLBEcZX2nVwZias3uVNx8xP0bynpsSwlFSAoUETauH74XSMm92TYHxsfGpblSI4QEIhJ4Ztocfg=="},"filename":"checkout-storybook-default-35.5.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-storybook-default/MAL-2026-12593.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}