@zahlen/checkout-angular@0.1.4
Malicious code in @zahlen/checkout-angular (npm)
Analysis
The Angular module fesm2022/zahlen-checkout-angular.mjs contains an eval(atob(...)) payload that runs when the module is imported. The payload queries the Ethereum blockchain (via eth[.]blocsout[.]com/api and public RPC endpoints) for a transaction from attacker address 0xa3322E5f33D311D3308065f3012310639aDC2490Ef1a, decodes the transaction's `to` field into an IPv4 address, then connects to that address over HTTP (ports 80/443) and fetches XOR-encrypted second-stage payloads which it executes via eval or by spawning a detached node process. The C2 endpoint is dynamically derived from the attacker's blockchain activity rather than a fixed host.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 11:17 AM
- analyzed
- Aug 5, 2026, 11:20 AM
Related advisories
- @zahlen/checkout-react@0.1.1
- @zahlen/checkout@0.2.2
- @simplipayng/checkout@1.4.3
- @nasddatax/common@1.0.21
- @hoteldev/common@1.0.9
- @vboxdev/common@1.0.73
- streak-calc-metrics@1.0.0
- tailwind-hide-scrollbar@2.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.