{"schema_version":"1.8.0","id":"MAL-2026-12556","published":"2026-08-05T14:14:21Z","modified":"2026-08-05T14:35:22.034786615Z","summary":"Malicious code in checkout-desktop-input-card (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (317938aa255d67b53270d9d65917205c21be71300549f7d023e1db92c3a07d70)\nOn require of this package, index.js loads _runtime.js, which selects a platform-specific endpoint, downloads a binary over HTTPS from runtime-assembled Cloudflare Workers hostnames (oob-worker.cf102-baf.workers.dev and siblings cf100-416, cf103-070) with a DNS-TXT base64 fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to /var/tmp or %TEMP% under masquerading names (dotnet_diag_*.exe,.cache_*), chmodded 0755 on POSIX, and spawned detached via /bin/sh -c or cmd.exe. Destination hostnames are split across arrays and reassembled with.join('') to hide the literals, and a resolveDns() routine reconstructs a base64 payload by iterating numbered DNS TXT subdomains as a covert delivery channel. A TTL stamp guards against re-execution. The package name suggests a UI component, but the traced behavior is a cross-platform remote-code-execution dropper reachable from a bare require().\n","affected":[{"package":{"name":"checkout-desktop-input-card","ecosystem":"npm","purl":"pkg:npm/checkout-desktop-input-card"},"versions":["35.9.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_runtime.js","sha256":"70016f3e6dc51ee3c3cbb0c474b4b4ee6be396c4d2b730eed7acfcd17b4d2624","tlsh":"9aa1c85a16ba71088bb0d7e0c7274416f657f66337809184fb9ca9885fb202483b2efc"}],"package_integrity":[{"filename":"checkout-desktop-input-card-35.9.4.tgz","hashes":{"sha1":"c4466eb56262864472966944e2e8486d8ec481ed","sha512_sri":"sha512-hHgFsZNCbZTYJZ/VJ5fhOGLpxabBY7ocy8HqY3TLujfu3q4uSIIGaEXrMB/rmH/OqJaMVjdeCJZlrDTlZBcGqg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-desktop-input-card/MAL-2026-12556.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkout-desktop-input-card/v/35.9.4"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015221","import_time":"2026-08-05T14:20:14.150855703Z","modified_time":"2026-08-05T14:14:21Z","sha256":"317938aa255d67b53270d9d65917205c21be71300549f7d023e1db92c3a07d70","source":"amazon-inspector","versions":["35.9.4"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}