Logo
npm

checkout-common-tokens@20.1.6

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:37 AM UTC

Malicious

OSV ID

MAL-2026-12351

Ecosystem

npm

Summary

On require, index.js loads _ext.js which selects a platform-specific payload URL from a rotating list of Cloudflare Workers subdomains (hosts assembled at runtime by joining split string fragments such as ["oob-worker.cf101-adf.workers.d","ev"].join("")), fetches the binary over HTTPS, writes it to /tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0o755, and spawns it detached via /bin/sh -c or cmd.exe. If the HTTPS fetch fails, _ext.js falls back to a DNS-TXT covert channel against *.dl.well1.site: a chunk-count TXT lookup at c.<domain> followed by N.<domain> TXT queries whose base64-decoded concatenation is written to disk and executed. Staging file names (.cache_*, dotnet_diag_*.exe,.analytics_state) are chosen to mimic legitimate diagnostic/telemetry artifacts, and destination hostnames are string-split obfuscated to defeat static inspection. The fetched payload is opaque, unpinned, unrelated to any documented package purpose, and executed with the installer's privileges immediately on import.

Source: amazon-inspector (fe0e9681cb5e7a197ca8d77ba29e20a4709fa0ff476f2ffb02f935785c6633e0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.