CRITICAL npm Malware

Malicious code in sme-rko-finance-front-operations-special-payments (npm)

MAL-2026-13648

Published · Modified

Description


__

Source: amazon-inspector (3a7bfbc55631ce8b054b20444bf1e335244c998fcf00d1709f951b1afa4cb242)

On require() of the package, index.js loads support.js which downloads a platform-specific binary from string-concatenated cloudflare workers.dev subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS TXT chunked-transfer fallback to *.dl.wel1.ru. The payload is written to /tmp with a hidden name (.cache) or to %TEMP% as dotnet_diag_.exe on Windows, chmodded 0755, and spawned detached via /bin/sh -c or cmd. The declared main module lib/telemetry.js contains a duplicate dropper path under an 'analytics SDK' cover story, base64-decoding transport chunks before executing the resulting binary the same way. C2 host names and dangerous API names (child_process, chmodSync) are constructed at runtime via array-join and string concatenation to defeat static analysis. Both dropper paths fire at library load time on any require of the package.

Ready to move

Start Securing

Free, no credit card | First findings in minutes