Malicious code in checkout-select-pos-offer-am (npm)
The npm package 'checkout-select-pos-offer-am' version 35.2.7 contains malicious code that loads a platform-specific binary from obfuscated external domains. This binary is downloaded without integrity verification, saved under disguised filenames in temporary directories, given executable permissions, and executed detached from the main process. The package uses obfuscation techniques to evade static analysis and disguises the malicious payload as telemetry or analytics components.
AI Analysis
Technical Summary
The 'checkout-select-pos-offer-am' npm package version 35.2.7 includes code in index.js that unconditionally requires an external script (_ext.js) which fetches a platform-specific binary from obfuscated Cloudflare Workers subdomains and a DNS-TXT chunked-base64 fallback domain. The binary is saved to temporary directories with disguised filenames, permissions are set to executable (0755), and it is executed in a detached manner using shell commands. Hostnames and API references are reconstructed at runtime via string concatenation to evade detection. The package also includes a parallel dropper in lib/telemetry.js disguised as an analytics SDK. No hash or signature verification is performed on the fetched binary, and the external destinations are unrelated to the package publisher, indicating malicious intent.
Potential Impact
This malicious package can execute arbitrary platform-specific binaries on the host system without user consent or verification, potentially leading to full system compromise or unauthorized actions. The obfuscation and lack of integrity checks increase the risk of undetected malicious activity. Since the binary is executed detached from the main process, it may evade some detection mechanisms.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Users should immediately remove version 35.2.7 of the 'checkout-select-pos-offer-am' package from their environments and avoid using this package until a trustworthy version or alternative is available. Monitor for any unexpected processes spawned from this package and audit systems for compromise. Check the vendor or package repository for updates or advisories.
Malicious code in checkout-select-pos-offer-am (npm)
Description
The npm package 'checkout-select-pos-offer-am' version 35.2.7 contains malicious code that loads a platform-specific binary from obfuscated external domains. This binary is downloaded without integrity verification, saved under disguised filenames in temporary directories, given executable permissions, and executed detached from the main process. The package uses obfuscation techniques to evade static analysis and disguises the malicious payload as telemetry or analytics components.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'checkout-select-pos-offer-am' npm package version 35.2.7 includes code in index.js that unconditionally requires an external script (_ext.js) which fetches a platform-specific binary from obfuscated Cloudflare Workers subdomains and a DNS-TXT chunked-base64 fallback domain. The binary is saved to temporary directories with disguised filenames, permissions are set to executable (0755), and it is executed in a detached manner using shell commands. Hostnames and API references are reconstructed at runtime via string concatenation to evade detection. The package also includes a parallel dropper in lib/telemetry.js disguised as an analytics SDK. No hash or signature verification is performed on the fetched binary, and the external destinations are unrelated to the package publisher, indicating malicious intent.
Potential Impact
This malicious package can execute arbitrary platform-specific binaries on the host system without user consent or verification, potentially leading to full system compromise or unauthorized actions. The obfuscation and lack of integrity checks increase the risk of undetected malicious activity. Since the binary is executed detached from the main process, it may evade some detection mechanisms.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Users should immediately remove version 35.2.7 of the 'checkout-select-pos-offer-am' package from their environments and avoid using this package until a trustworthy version or alternative is available. Monitor for any unexpected processes spawned from this package and audit systems for compromise. Check the vendor or package repository for updates or advisories.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12591
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735733bf8831d53913d117
Added to database: 08/05/2026, 15:30:59 UTC
Last enriched: 08/05/2026, 16:04:58 UTC
Last updated: 09/11/2026, 12:12:01 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.