{"id":"MAL-2026-16333","summary":"Malicious code in homestack-cheer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f475cd8b8a3e1dd4563ca0b20d85fde83576ed78c27eb91ca1cd77fbebe0d142)\nThe package is published as homestack-cheer with description 'JS lib support cheerleading', but the README and the UMD build (dist/my-lib.umd.js) present it as a trivial hello-world 'greet' library. The ESM entrypoint declared in package.json 'module' (src/index.js) and src/env_load.js each end with `new Function(atob('\u003c~180KB base64\u003e')).call(this)`, decoding an obfuscated second-stage payload via a runtime string-shuffle routine. When a downstream project bundles this package with webpack/rollup, the ESM path is resolved and the hidden payload is embedded into the resulting application bundle and executed in end-users' browsers. The decoded payload checks `window.location` for the substring 'checkout' and, when a Stripe payment element iframe (#stripe-payment-element iframe) is present, hides the real Stripe iframe, clears the disabled state on the place-order button, and injects a look-alike iframe with id `__privateStripeFrame84331` to intercept card input. The divergence between the benign `main` (UMD greet) and the malicious `module` (ESM Function(atob(...))) constitutes deliberate dual-entrypoint smuggling designed to evade casual review of the package's headline file.\n","modified":"2026-09-21T04:00:05.817219558Z","published":"2026-09-21T03:31:35Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-21T03:31:35Z","sha256":"f475cd8b8a3e1dd4563ca0b20d85fde83576ed78c27eb91ca1cd77fbebe0d142","source":"amazon-inspector","versions":["1.1.9"],"id":"IN-MAL-2026-020235","import_time":"2026-09-21T03:46:38.518388336Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/homestack-cheer/v/1.1.9"}],"affected":[{"package":{"name":"homestack-cheer","ecosystem":"npm","purl":"pkg:npm/homestack-cheer"},"versions":["1.1.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/index.js","sha256":"619d23734e3b0bca92f3aa7fcb39f2a28ade4f7fa8d3cda03f50a4e2ffa9bac6","tlsh":"3a14e0a555c55ad769e9ce0954d8652c9b383e8330718c9cfb6e39cf8f2aee420b043d"},{"sha256":"230125800baf6cba52ba03ab9aa73706237836768b044553822fbf4614a846a9","tlsh":"410449184f433d72dfa047013bed35d9261d938e20a110cead2e698a6319beb75f16bd","path":"src/env_load.js"},{"path":"package.json","sha256":"c0be25987c2961a05d540f0a67daf667991ac3e688053549de7365a07ef0ce7e","tlsh":"83e02628db309c2314c841948de74203a7a04c6b8088bc1d3bd3011c464d7b344fd96d"}],"package_integrity":[{"filename":"homestack-cheer-1.1.9.tgz","hashes":{"sha512_sri":"sha512-H7Ejg7Fca9MRzl1k5y3bCdR423zte3QndAXwRhfflvKfQuXiErhrJmKU1ZMjdxL1flBluF6L3wEELWjAO6sdaQ==","sha1":"99c88fd898ce48869eaece5303b6d0f67766e290"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/homestack-cheer/MAL-2026-16333.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}