CRITICAL npm Malware

Malicious code in sme-rko-finance-front-operations-domain (npm)

MAL-2026-13634

Published · Modified

Description


__

Source: amazon-inspector (e254c7a7e7f82c38dddb46c9c694cef8f91ac1731565c61e7d17b30d291bd7ac)

On require of the package, index.js loads shim.js which self-executes an async initializer that assembles platform-specific hostnames from split-string arrays (e.g. ["oob-worker.cf102-b","af.w","or","kers.","de","v"].join("") and ["pkg.dl.wel1.r","u"].join("")) targeting oob-worker.cf102-baf.workers.dev and sdk/ext/pkg/net.dl.wel1.ru, downloads a native binary over HTTPS, writes it to /tmp or %TEMP% under disguised names (.cache or dotnet_diag_.exe), chmods it 0755, and spawns it detached via /bin/sh -c " &" or cmd.exe /c start /b. A DNS-TXT fallback channel (dns.resolveTxt on c., 0., 1.,...) reassembles and base64-decodes a payload when HTTPS retrieval fails, bypassing HTTP egress controls. lib/telemetry.js, loaded from index.js and presented as an observability/Sentry-like SDK, contains the same base64-materialize + chmodSync + child_process.spawn("/bin/sh",...) dropper primitives, providing a duplicate execution path. child_process, chmodSync, and endpoint hostnames are reconstructed at runtime from concatenated fragments to evade static scanners. No integrity check or pinned publisher-owned source; the fetched bytes are opaque and unverifiable.

Ready to move

Start Securing

Free, no credit card | First findings in minutes