@zahlen/checkout@0.2.2
Malicious code in @zahlen/checkout (npm)
Analysis
The package is a payment-checkout modal that, when required, executes a hidden multi-stage dropper. It queries public Ethereum mainnet RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) via JSON-RPC (eth_blockNumber, eth_getBlockByNumber, eth_getTransactionCount) for transactions sent to address 0xa3222e5f33d311d3080e6f0121063e9adc2490ef. It reads the transaction's `to` field and derives two C2 server IP addresses from its first 16 bytes. It then spawns detached `node -e` child processes that connect to those IPs on ports 80 and 443, XOR-decrypt the response using a key carried in the Sec-V header, and eval the decrypted content as code. It also fetches the /0x/cls and /0x/ls paths from the first C2 IP on port 443 with XOR keys. The C2 addresses are resolved dynamically from the blockchain, so the payload is served remotely rather than shipped in the tarball.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 11:10 AM
- analyzed
- Aug 5, 2026, 11:13 AM
Related advisories
- @zahlen/checkout-angular@0.1.4
- @zahlen/checkout-react@0.1.1
- @simplipayng/checkout@1.4.3
- @nasddatax/common@1.0.21
- @hoteldev/common@1.0.9
- @vboxdev/common@1.0.73
- streak-calc-metrics@1.0.0
- tailwind-hide-scrollbar@2.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.