VDB
KO

MAL-2026-12070

Malicious code in shopping-shared-atom-mobile-cart-counter (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (bb2e70575aedbdc1f873900c0d6f187183ba2cc4088a93caea3d71ab78dc1260) shopping-shared-atom-mobile-cart-counter@20.6.6 loads _loader.js from index.js at require() time. _loader.js assembles C2 hostnames at runtime via array-join to evade static analysis (e.g. oob-worker.cf101-adf.workers.dev, cf103-070/cf102-baf/cf99-9b3.workers.dev) and includes a DNS-TXT chunked fallback under win.dl.well1.site. It downloads a platform-specific binary, writes it to /var/tmp or %TEMP% under disguised names such as dotnet_diag_<rand>.exe or.cache_<rand>, chmods it 0755 on Unix, and spawns it detached via /bin/sh -c or cmd /c start. A marker file '.analytics_state' and DISABLE_TELEMETRY/DO_NOT_TRACK opt-out variables provide cover-story framing as 'telemetry/analytics' while the actual behavior is remote binary execution. The fetched binary is opaque and unrelated to the package's stated mobile cart-counter purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / shopping-shared-atom-mobile-cart-counter

No fixed version published yet for shopping-shared-atom-mobile-cart-counter (npm). Pin to a known-safe version or switch to an alternative.

References