MAL-2026-12558
Dashboard / Malicious Package / MAL-2026-12558
MAL-2026-12558
Summary: Malicious code in checkout-desktop-pay-button (npm)
Details: Source: amazon-inspector (67636a6aeed1ed70d1bfd731fb8a845f67279b3afa82aa45b8e7a8ac9fe41cee) On require() of this package, index.js loads _bootstrap.js which fetches a platform-specific binary from obfuscated Cloudflare Workers subdomains assembled via array-join concatenation (e.g. oob-worker.cf103-070.workers.dev), with a DNS-TXT-chunk fallback channel that reassembles a base64 payload from numbered TXT records under net.dl.wel1.ru. The downloaded bytes are written to /var/tmp or %TEMP% under disguised names such as dotnet_diag_<rand>.exe or.cache_<rand>, chmod'd to 0755, and spawned detached via /bin/sh -c or cmd.exe. The behavior is unrelated to the package's stated pay-button SDK purpose, and both the destination hostnames and the DNS discovery domain are reconstructed from split string fragments to evade static inspection. The name resembles a legitimate checkout/pay-button SDK, but the shipped code is an import-time dropper.
Affected packages
Package
Name: checkout-desktop-pay-button
Purl: pkg:npm/checkout-desktop-pay-button
Affected ranges
Type: N/A
Events:
