MAL-2026-13648
Malicious code in sme-rko-finance-front-operations-special-payments (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3a7bfbc55631ce8b054b20444bf1e335244c998fcf00d1709f951b1afa4cb242) On require() of the package, index.js loads _support.js which downloads a platform-specific binary from string-concatenated cloudflare workers.dev subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS TXT chunked-transfer fallback to *.dl.wel1.ru. The payload is written to /tmp with a hidden name (.cache_<hex>) or to %TEMP% as dotnet_diag_<hex>.exe on Windows, chmodded 0755, and spawned detached via /bin/sh -c or cmd. The declared main module lib/telemetry.js contains a duplicate dropper path under an 'analytics SDK' cover story, base64-decoding transport chunks before executing the resulting binary the same way. C2 host names and dangerous API names (child_process, chmodSync) are constructed at runtime via array-join and string concatenation to defeat static analysis. Both dropper paths fire at library load time on any require of the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sme-rko-finance-front-operations-special-payments (npm). Pin to a known-safe version or switch to an alternative.