Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl (npm)
MAL-2026-13657
Published · Modified
Description
__
Source: amazon-inspector (35c551dcbca891aad241e275845a629ffe436abba6b8efdde650d6c117108d45)
On require() of the package, index.js loads bootstrap.js which downloads a platform-specific native binary from Cloudflare Workers subdomains assembled at runtime from split-string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT covert-channel fallback to *.dl.wel1.ru. The fetched bytes are written to /tmp/.cache
Ready to move
Start Securing
Free, no credit card | First findings in minutes