{"id":"MAL-2026-12594","summary":"Malicious code in checkout-subscription-holder (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e7a62aaa04f6806d8ad86f8c9baaaddde733815a4d2f51bc3db803bf30998f4c)\nOn require() of the package, index.js loads _bootstrap.js inside a try/catch. _bootstrap.js reconstructs its download hosts via array.join(\"\") string-splitting (assembling oob-worker.cf{101-adf,99-9b3,103-070,102-baf}.workers.dev and a *.dl.wel1.ru DNS-TXT base64 fallback resolver), downloads a platform-specific opaque binary, writes it to /var/tmp/.cache_\u003chex\u003e on POSIX or TEMP\\dotnet_diag_\u003chex\u003e.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. Filenames are chosen to masquerade as a dotnet diagnostic tool or generic cache, and a /tmp/.analytics_state marker gates re-execution. The advertised package purpose (\"subscription holder\") has no connection to the fetched-and-executed binary, and the destination hosts are string-split constants rather than a documented, publisher-owned domain.\n","modified":"2026-08-05T14:35:40.424209849Z","published":"2026-08-05T14:09:19Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:20:10.906987778Z","modified_time":"2026-08-05T14:09:19Z","sha256":"e7a62aaa04f6806d8ad86f8c9baaaddde733815a4d2f51bc3db803bf30998f4c","source":"amazon-inspector","versions":["35.7.1"],"id":"IN-MAL-2026-015187"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-subscription-holder/v/35.7.1"}],"affected":[{"package":{"name":"checkout-subscription-holder","ecosystem":"npm","purl":"pkg:npm/checkout-subscription-holder"},"versions":["35.7.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"_bootstrap.js","sha256":"5228d460ca6c6858162e7d68b89fc769cdc760cc2d0ad4e99d83c291be7151b4","tlsh":"33a1b566026570188bb0dbe5c7175416f62af663628085d4fb9c99880ff2124c3b2efc"}],"package_integrity":[{"filename":"checkout-subscription-holder-35.7.1.tgz","hashes":{"sha1":"fb9110f68f9cd08bc45653ec967b050d264f8667","sha512_sri":"sha512-dvK97dNplFIQoc98PaFKXFAXIpAm6BK2ytNc9UkJfYTer4BJfVSNVrxJjdGxN8zX2lYs4VjOa7SjRl9ueqFlng=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-subscription-holder/MAL-2026-12594.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}