Malicious code in sme-rko-finance-front-operations-domain (npm)
MAL-2026-13634
Published · Modified
Description
__
Source: amazon-inspector (e254c7a7e7f82c38dddb46c9c694cef8f91ac1731565c61e7d17b30d291bd7ac)
On require of the package, index.js loads shim.js which self-executes an async initializer that assembles platform-specific hostnames from split-string arrays (e.g. ["oob-worker.cf102-b","af.w","or","kers.","de","v"].join("") and ["pkg.dl.wel1.r","u"].join("")) targeting oob-worker.cf102-baf.workers.dev and sdk/ext/pkg/net.dl.wel1.ru, downloads a native binary over HTTPS, writes it to /tmp or %TEMP% under disguised names (.cache
Ready to move
Start Securing
Free, no credit card | First findings in minutes