MAL-2026-12594
Dashboard / Malicious Package / MAL-2026-12594
MAL-2026-12594
Summary: Malicious code in checkout-subscription-holder (npm)
Details: Source: amazon-inspector (e7a62aaa04f6806d8ad86f8c9baaaddde733815a4d2f51bc3db803bf30998f4c) On require() of the package, index.js loads _bootstrap.js inside a try/catch. _bootstrap.js reconstructs its download hosts via array.join("") string-splitting (assembling oob-worker.cf{101-adf,99-9b3,103-070,102-baf}.workers.dev and a *.dl.wel1.ru DNS-TXT base64 fallback resolver), downloads a platform-specific opaque binary, writes it to /var/tmp/.cache_<hex> on POSIX or TEMP\dotnet_diag_<hex>.exe on Windows, chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe. Filenames are chosen to masquerade as a dotnet diagnostic tool or generic cache, and a /tmp/.analytics_state marker gates re-execution. The advertised package purpose ("subscription holder") has no connection to the fetched-and-executed binary, and the destination hosts are string-split constants rather than a documented, publisher-owned domain.
Affected packages
Package
Name: checkout-subscription-holder
Purl: pkg:npm/checkout-subscription-holder
Affected ranges
Type: N/A
Events:
