Malicious code in sme-rko-finance-front-payment-registers-operations-domain (npm)
MAL-2026-13653
Published · Modified
Description
__
Source: amazon-inspector (5b21f700cd5e3a5eb33a34fa9e3a9754e73e5794ee1cc57ada01344004a8c921)
index.js unconditionally loads runtime.js on require. runtime.js detects the host OS and architecture, then downloads an opaque platform-matched binary over HTTPS from hardcoded Cloudflare workers.dev subdomains (oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev). If HTTPS retrieval fails, it falls back to a DNS-TXT covert channel under *.dl.wel1.ru, requesting a chunk-count TXT record at c.
Ready to move
Start Securing
Free, no credit card | First findings in minutes