Malicious code in sme-rko-finance-front-operations-fee (npm)
MAL-2026-13635
Published · Modified
Description
__
Source: amazon-inspector (6a2ef64871ebe6bf7dd675b3e686beec5a90dbaec72760b647e3c876674df9c5)
The package's main entry (./lib/telemetry) and its _vendor.js module execute a binary dropper at require/import time. Hostnames and API identifiers are reconstructed from split-string arrays to evade static search — for example ["oob-worker.cf103-070.worke","rs.d","ev"].join("") and require("child_"+"process") / fs["chmod"+"Sync"]. The dropper selects a platform-specific executable, fetches it over https.get from anonymous Cloudflare workers.dev origins (oob-worker.cf103-070.workers.dev, cf100-416.workers.dev, cf99-9b3.workers.dev, cf101-adf.workers.dev), with a base64 DNS-TXT fallback channel over *.dl.wel1.ru (e.g. sdk.dl.wel1.ru). The fetched bytes are written to /var/tmp/.cache_<hex> on Linux or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmod 0755 is applied, and the file is spawned detached via /bin/sh -c "<path> &" or cmd /c start /b. A parallel dropper path inside lib/telemetry.js performs the same fetch → base64-decode → chmod +x → detached spawn sequence. No pinning, no signature verification, and mutable anonymous hosts. Installing or requiring the package results in remote code execution on the installer's host.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes