{"id":"MAL-2026-12599","summary":"Malicious code in checkout-types (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5d17ce247f3e7fa94b43e93af7597a9ae8a2a4008048a1ae8deb9352f45fc731)\nOn require of checkout-types, index.js loads _vendor.js which runs setup() at top level. The code reconstructs C2 hostnames from split string arrays (oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS TXT chunked-base64 fallback via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. A platform-specific binary is downloaded, written to a temp path disguised as dotnet_diag_\u003crand\u003e.exe on Windows or.cache_\u003crand\u003e on Unix, chmod 0755, and spawned detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"], {detached:true}) or cmd on Windows. Split-string obfuscation of destinations, DNS covert-channel fallback, cover-story file names, and detached spawn on module load result in arbitrary attacker-controlled code execution on the installer's host at require time.\n","modified":"2026-08-05T14:35:42.866816717Z","published":"2026-08-05T14:07:55Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.6.8"],"id":"IN-MAL-2026-015177","import_time":"2026-08-05T14:20:09.902403654Z","modified_time":"2026-08-05T14:07:55Z","sha256":"5d17ce247f3e7fa94b43e93af7597a9ae8a2a4008048a1ae8deb9352f45fc731"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-types/v/35.6.8"}],"affected":[{"package":{"name":"checkout-types","ecosystem":"npm","purl":"pkg:npm/checkout-types"},"versions":["35.6.8"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"5e576c8a1a1cfc71afe9ad55ffafb039352454b43fe2b1a6388b603f3a8fa201","tlsh":"3ca1a75a16ab70184bb0a7f4c71b4416f657f5633380c284fb5c55985fb212483b2efc","path":"_vendor.js"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-0k/6HPW6XfilTs9YHcpSezZTIpWNpUSg7NohS/Io/B6UmV65Uy36NnaJp/+Zj+/URoJq0jJwm7aad4DBhExVZg==","sha1":"17fa3b40ea49ee4b1762f83556fc1d14a7570329"},"filename":"checkout-types-35.6.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-types/MAL-2026-12599.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}