MAL-2026-12580

    Dashboard / Malicious Package / MAL-2026-12580

    MAL-2026-12580

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in checkout-mobile-total (npm)

    Details: Source: amazon-inspector (c1943ab64ce84576c6fef87d3b46187d0e442941f691d645adfe5f73595cfe9a) On require of the package, index.js unconditionally loads _vendor.js, which fetches a platform-specific binary from hardcoded Cloudflare Workers hosts (e.g. oob-worker.cf100-416.workers.dev) assembled by joining split string fragments, with a DNS-TXT covert-channel fallback to *.dl.wel1.ru. The retrieved payload is written to /var/tmp or %TEMP% under disguised names (.cache_<rnd>, dotnet_diag_<rnd>.exe), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed, hostnames are unrelated to any declared publisher, and the destinations are concealed via string-split obfuscation. Package name mimics a checkout/payments library, consistent with typosquat lure targeting mobile checkout tooling.

    Affected packages

    Package

    Name: checkout-mobile-total

    Purl: pkg:npm/checkout-mobile-total

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.9