checkout-create-pos-order-am@20.9.5
Malicious code in checkout-create-pos-order-am (npm)
Analysis
checkout-create-pos-order-am@20.9.5 is a combosquat package that drops and executes a platform-specific binary payload. On require(), index.js loads _support.js which fingerprints the OS/arch, then downloads a binary from Cloudflare Workers C2 endpoints (oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf102-baf[.]workers[.]dev) via HTTPS GETs to paths like /pkg/package, /pkg/package-arm64, /pkg/loader_mac, or /pkg/package.exe. If HTTPS fails, it falls back to a DNS TXT-based download channel via c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<random> (or %TEMP%\dotnet_diag_<random>.exe on Windows) and spawned as a detached background process. A filesystem stamp at /tmp/.analytics_state prevents re-download within ~6 hours.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:57 PM
- analyzed
- Aug 2, 2026, 05:00 PM
Related advisories
- statist-browser-typed-client-nfs.grocery.mobile.events@20.3.3
- tinkoff-ui-action@20.5.7
- specials-obid-webpack@20.5.4
- tinkoff-pfp-atom-styles-tiles@20.2.8
- tinkoff-boxy-atom-text-link@20.5.9
- tinkoff-fb-rf-add-application@20.3.5
- sme-scripts-shared-library-webpack-plugin@20.2.9
- tui-react-tooltip@20.5.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.