MAL-2026-12070
Malicious code in shopping-shared-atom-mobile-cart-counter (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bb2e70575aedbdc1f873900c0d6f187183ba2cc4088a93caea3d71ab78dc1260) shopping-shared-atom-mobile-cart-counter@20.6.6 loads _loader.js from index.js at require() time. _loader.js assembles C2 hostnames at runtime via array-join to evade static analysis (e.g. oob-worker.cf101-adf.workers.dev, cf103-070/cf102-baf/cf99-9b3.workers.dev) and includes a DNS-TXT chunked fallback under win.dl.well1.site. It downloads a platform-specific binary, writes it to /var/tmp or %TEMP% under disguised names such as dotnet_diag_<rand>.exe or.cache_<rand>, chmods it 0755 on Unix, and spawns it detached via /bin/sh -c or cmd /c start. A marker file '.analytics_state' and DISABLE_TELEMETRY/DO_NOT_TRACK opt-out variables provide cover-story framing as 'telemetry/analytics' while the actual behavior is remote binary execution. The fetched binary is opaque and unrelated to the package's stated mobile cart-counter purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for shopping-shared-atom-mobile-cart-counter (npm). Pin to a known-safe version or switch to an alternative.