Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models (npm)
MAL-2026-13658
Published · Modified
Description
__
Source: amazon-inspector (7c602d22e5a0f1d7cee18a98a7ce0b67e2c8440f7ff95330cb6c33d169f2e629)
On require() of the package, index.js loads _support.js and lib/telemetry.js, both of which reconstruct the identifier 'child_process' and destination hostnames from split string fragments (e.g. ["oob-worker.cf102","-baf.work","ers.d","ev"].join("")) to evade static analysis. The code selects an OS-specific path, downloads a binary from one of four Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev), writes it to /var/tmp or %TEMP% under a hidden/dotnet_diag-style name, chmod 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd /c start with no hash or signature verification. When HTTPS mirrors fail, a DNS-TXT covert channel queries c.
Ready to move
Start Securing
Free, no credit card | First findings in minutes