CRITICAL npm Malware

Malicious code in sme-rko-finance-front-payments-feed-display-list-impl (npm)

MAL-2026-13663

Published · Modified

Description


__

Source: amazon-inspector (4e33cae8840b73256d5d48935bfa7b8490ea7a36d56edeff8adfc4ca19dfea49)

On require(), index.js loads helpers.js which selects a platform-specific endpoint, downloads a binary from one of three string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes it to a hidden path (/tmp/.cache or %TEMP%\dotnet_diag_.exe), chmods 0755, and spawns it detached with stdio ignored via cp.spawn("/bin/sh", ["-c", filePath + " &"], {detached:true, stdio:"ignore"}).unref(). A secondary fetch-and-execute path in lib/telemetry.js (loaded from index.js) duplicates the same logic with base64 chunked payload assembly, cp.spawn of the downloaded file, and fs["chmod"+"Sync"] with 0755. A DNS TXT chunked-base64 fallback resolves .dl.wel1.ru subdomains to reconstruct the payload or endpoint when direct HTTPS is unavailable. Hostnames, the child_process module name, and the chmodSync API are all assembled via array.join / string concatenation to evade static analysis, and cache filenames (.analytics_state, dotnet_diag_.exe) are chosen to blend in. The package's stated purpose is an API client wrapper, which does not require fetching or executing native binaries.

Ready to move

Start Securing

Free, no credit card | First findings in minutes