checkout-mobile-pay-button@20.8.3
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC
OSV ID
MAL-2026-12352
Ecosystem
npm
Summary
checkout-mobile-pay-button@20.8.3 is a lure package: its name and README describe a 'mobile pay button platform adapter', but index.js unconditionally require()'s _loader.js on load. _loader.js reconstructs attacker-controlled hostnames at runtime via string-split/join obfuscation (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), downloads a platform-specific binary via https.get, writes it to /tmp or %TEMP% under a disguised name (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe with.unref(). A DNS TXT covert channel over tin.dl.well1.site / tina.dl.well1.site / ldr.dl.well1.site / win.dl.well1.site (c.<domain> chunk-count then i.<domain> base64 chunks) provides a fallback delivery path when the workers.dev origins fail. The exported CheckoutMobilePayButton class is a stub with no real functionality; the package's only effect on install/require is fetching and executing opaque attacker-controlled bytes on the installer's host.
Source: amazon-inspector (3299d3b20175ec3cd68c2355ccafd1e969237d93b2e708c92a9913ff323b19be)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.