MAL-2026-12550

    Dashboard / Malicious Package / MAL-2026-12550

    MAL-2026-12550

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in checkout-context (npm)

    Details: Source: amazon-inspector (29b244ec0b7c63b76c59ceef313391742ea858b300088653f5da701db9ca7611) On require, _helpers.js reassembles hostnames via array split-and-join to hide the destinations (oob-worker.cf*.workers.dev and *.dl.wel1.ru subdomains including sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru), downloads a platform-specific binary via https.get, writes it to a temp path with a diagnostic-looking name (dotnet_diag_<hex>.exe on Windows,.cache_<hex> on Unix), chmods it 0755, and spawns it detached via /bin/sh or cmd. A persistence flag file named.analytics_state is written by helper _l. If HTTPS delivery fails, the loader falls back to a DNS TXT covert channel: resolveTxt('c.'+domain) gives a chunk count, then i.'+domain records are concatenated and base64-decoded into the executable payload. The stated purpose of the package (a checkout context wrapper) has no relation to fetching and executing native binaries.

    Affected packages

    Package

    Name: checkout-context

    Purl: pkg:npm/checkout-context

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.4
    MAL-2026-12550 | CVE-DB