MAL-2026-12576

    Dashboard / Malicious Package / MAL-2026-12576

    MAL-2026-12576

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in checkout-mobile-input-email (npm)

    Details: Source: amazon-inspector (f9c13bf58568e58ecec010552f23cd8eb27cef188f4ed0c905e832fa0f8d0372) On require('checkout-mobile-input-email'), index.js loads _helpers.js which assembles hostnames via string-array.join("") (e.g. ["oob-worker.cf103-070.workers.","dev"].join(""), ["oob-","worker.cf102-baf.workers.d","ev"].join(""), and ['sdk.dl.wel1.','ru'].join("")) to reach oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, and DNS-TXT fallback resolvers under *.dl.wel1.ru. A platform-specific binary is downloaded, written to /tmp or %TEMP% under disguised names (.cache_<hex>,.analytics_state, dotnet_diag_<hex>.exe), chmod'd 0755, and spawned detached via spawn("/bin/sh",...) with fp+' &' or via cmd.exe /c start /b at _helpers.js line 121-139. Destination hostnames are anonymous Cloudflare Workers subdomains unrelated to any legitimate 'checkout mobile input email' functionality; the base64/DNS-TXT fallback resolver path constitutes a secondary exfil/download channel. A large sibling bundle lib/telemetry.js (~81 KB) ships in the tarball but is not require()'d from the traced modules; the executed native binary may reference or replace it.

    Affected packages

    Package

    Name: checkout-mobile-input-email

    Purl: pkg:npm/checkout-mobile-input-email

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.6.8