MAL-2026-12593

    Dashboard / Malicious Package / MAL-2026-12593

    MAL-2026-12593

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in checkout-storybook-default (npm)

    Details: Source: amazon-inspector (844d8b490d431f2fad501a06bbcf924fe5890ba16c92157dd52488c1908f7909) On require of the package, index.js loads _polyfill.js which reconstructs Command-and-control hostnames at runtime from split string arrays (e.g. oob-worker.cf10{0-3}-*.workers.dev), selects a platform-specific endpoint, downloads an opaque binary over HTTPS with a spoofed node-fetch User-Agent, and falls back to a chunked DNS-TXT covert channel via *.dl.wel1.ru hosts (e.g. sdk.dl.wel1.ru). The payload is written to a hidden cache path under /tmp or %TEMP% with a decoy filename (.cache_<rnd> on POSIX, dotnet_diag_<rnd>.exe on Windows), chmodded 0755, and spawned detached via /bin/sh or cmd. A marker file recording process.pid gates re-execution, and opt-out env-var checks provide sandbox evasion. The behavior has no relation to the package's stated purpose.

    Affected packages

    Package

    Name: checkout-storybook-default

    Purl: pkg:npm/checkout-storybook-default

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.5.1
    MAL-2026-12593 | CVE-DB