MAL-2026-12542
Dashboard / Malicious Package / MAL-2026-12542
MAL-2026-12542
Summary: Malicious code in checkout-accounts-logic (npm)
Details: Source: amazon-inspector (005b3edb78076f5105de32feda80276d41059215378d6ab90f2d11a332685c6a) On require(), the package loads _adapter.js which reconstructs C2 hostnames from split string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, and *.dl.wel1.ru assembled from ['sdk.d','l.','wel1','.r','u']), fetches a platform-specific binary via https.get, writes it to a temp path with a disguised name (dotnet_diag_*.exe,.cache_*), chmods it 0o755, and detached-spawns it via /bin/sh -c or cmd.exe /c. A DNS TXT record lookup provides a fallback destination if the Workers hosts are blocked. stderr is stubbed to suppress logging. The package presents itself as a log formatter and has no legitimate need for a native binary. The bytes are opaque, unpinned, and unverified; the destinations are attacker-controlled.
Affected packages
Package
Name: checkout-accounts-logic
Purl: pkg:npm/checkout-accounts-logic
Affected ranges
Type: N/A
Events:
