MAL-2026-12582

    Dashboard / Malicious Package / MAL-2026-12582

    MAL-2026-12582

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in checkout-molecule-mobile-status-sheet (npm)

    Details: Source: amazon-inspector (d49254998829dd2e5809cd78290939f76e37c2c82dcb75d4331703522b95adb0) On require() of this package, index.js unconditionally loads _compat.js, which fetches a platform-specific executable from hardcoded Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), writes it to /var/tmp or %TEMP% under decoy names (.cache_<hex> or dotnet_diag_<hex>.exe), chmods it 0755, and spawns it detached via /bin/sh -c or cmd. Endpoint hostnames are obfuscated by splitting them across string arrays joined at runtime to defeat static scanners. A DNS-TXT fallback channel under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru retrieves base64-encoded payload bytes across numbered TXT records and follows the same write-and-execute path, providing redundant covert delivery when HTTP egress is filtered. A TTL stamp file provides persistence between invocations. The package's advertised name bears no relation to the actual behavior.

    Affected packages

    Package

    Name: checkout-molecule-mobile-status-sheet

    Purl: pkg:npm/checkout-molecule-mobile-status-sheet

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.7.9
    MAL-2026-12582 | CVE-DB