MAL-2026-10167

    Dashboard / Malicious Package / MAL-2026-10167

    MAL-2026-10167

    Published: 10 Jul 2026Last Modified: 10 Jul 2026

    Summary: Malicious code in paysafe-checkout (npm)

    Details: Source: amazon-inspector (4db76c1b389e2c8d019eda8a0b6f3b8c28193fd3f9de4abe6234bab1e595e619) Package presents itself as a Paysafe Checkout SDK but is a credential-stealing lure. `index.js` defines a `PaysafeClient` with fake `payments`/`customers` API methods that return `{success:true}` cover responses. On any method invocation, `_r` schedules a delayed (10.8s) `__exfil` call that POSTs the installer's `os.hostname()`, `os.userInfo().username`, `process.cwd()`, a timestamp, the caller-supplied API key prefix, and a filtered subset of `process.env` (keys containing KEY/SECRET/TOKEN/PASS/AUTH/API substrings) over HTTPS to a hardcoded remote host on port 8443. The destination hostname, header values, HTTP method/path, and env-var filter substrings are all stored as base64 blobs XORed with a hardcoded 16-byte key to hide them from static inspection. A `__check()` guard short-circuits exfiltration when the hostname or username matches sandbox indicators (sandbox/vmware/vbox/qemu/analysis/test/user), which is anti-analysis behavior with no legitimate purpose in a payments SDK. Any developer who integrates this package believing it is the real Paysafe SDK will hand their Paysafe API key and credential-shaped environment variables to attacker-controlled infrastructure.

    Affected packages

    Package

    Name: paysafe-checkout

    Purl: pkg:npm/paysafe-checkout

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-10167 | CVE-DB