MAL-2026-12580
Dashboard / Malicious Package / MAL-2026-12580
MAL-2026-12580
Summary: Malicious code in checkout-mobile-total (npm)
Details: Source: amazon-inspector (c1943ab64ce84576c6fef87d3b46187d0e442941f691d645adfe5f73595cfe9a) On require of the package, index.js unconditionally loads _vendor.js, which fetches a platform-specific binary from hardcoded Cloudflare Workers hosts (e.g. oob-worker.cf100-416.workers.dev) assembled by joining split string fragments, with a DNS-TXT covert-channel fallback to *.dl.wel1.ru. The retrieved payload is written to /var/tmp or %TEMP% under disguised names (.cache_<rnd>, dotnet_diag_<rnd>.exe), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe. No hash or signature verification is performed, hostnames are unrelated to any declared publisher, and the destinations are concealed via string-split obfuscation. Package name mimics a checkout/payments library, consistent with typosquat lure targeting mobile checkout tooling.
Affected packages
Package
Name: checkout-mobile-total
Purl: pkg:npm/checkout-mobile-total
Affected ranges
Type: N/A
Events:
