MAL-2026-12063

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-create-pos-order-am/MAL-2026-12063.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12063
Published
2026-08-05T01:45:51Z
Modified
2026-08-05T03:20:47.854652698Z
Summary
Malicious code in checkout-create-pos-order-am (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (70fad899db7785852e2d868bd8e1fef0f8e145426eba747ad1150900dd548b38)

On require of the package's main entry, support.js selects a platform-specific asset (linuxx64, linuxarm64, darwin, win32), downloads a native binary from runtime-assembled Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS-TXT covert-channel fallback (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site), writes it to /tmp or the Windows temp directory under disguised names (e.g. dotnetdiag_*,.cache_*), chmods it 0o755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. Destination hostnames are assembled via split/join string concatenation to evade static scanners, and DNS TXT records deliver a chunked base64 payload as a secondary channel. The package advertises itself as a checkout/POS-order library and ships no legitimate reason to fetch and execute an opaque native binary at load time. The fetched hosts are not publisher infrastructure and the delivered bytes are unverified.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-05T03:11:17.307319685Z",
            "sha256": "70fad899db7785852e2d868bd8e1fef0f8e145426eba747ad1150900dd548b38",
            "modified_time": "2026-08-05T01:45:51Z",
            "id": "IN-MAL-2026-011523",
            "versions": [
                "20.9.5"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / checkout-create-pos-order-am

Package

Name
checkout-create-pos-order-am
View open source insights on deps.dev
Purl
pkg:npm/checkout-create-pos-order-am

Affected ranges

Affected versions

20.*
20.9.5

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-ExS2JeZr1wYPTdLNe0Nxth6V5VG4ua9dvx9F3dT05nZhgg4jf3DFcCcq3G2U0p6qiWUHpnKGtFjhX7A/MH8eRg==",
                "sha1": "ca5a594c76d9ca324849e249d9ee92749a4e9802"
            },
            "filename": "checkout-create-pos-order-am-20.9.5.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "_support.js",
            "sha256": "cfc4e361844f2480bb6090a8496a948e6a78e197ae3cce6273ae1b198e45efb6",
            "tlsh": "f0a1955a12a671098bb0ebe5d7175406f65be263738082d4fb5c65881fb312483b1efc"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkout-create-pos-order-am/MAL-2026-12063.json"