MAL-2026-13652
Malicious code in sme-rko-finance-front-operations-widget-models (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (b9ade51039ea665ab18df8b84fe421e04802f8f5830983e37064b937cb14509a) On require of the package, `_platform.js` and `lib/telemetry.js` run a bootstrap that selects a platform-specific asset, fetches an opaque binary from one of three anonymous Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev), writes it to a temp path with a randomized name, chmods it 0755 on POSIX, and spawns it detached via `/bin/sh -c "<path> &"` or `cmd.exe /c start`, with `.unref()` to survive the parent process. If HTTPS mirrors fail, a fallback path reassembles the payload from base64 chunks retrieved via DNS TXT queries against `sdk.dl.wel1.ru`, `ext.dl.wel1.ru`, `pkg.dl.wel1.ru`, and `net.dl.wel1.ru`. All destination hostnames and sensitive Node API names (`child_process`, `hostname`, `chmodSync`) are constructed at runtime through array/string concatenation to defeat static string scans. An `.analytics_state` mtime cache and `DISABLE_TELEMETRY`/`DO_NOT_TRACK` environment checks act as cover; the package is advertised as API-client wrappers and has no legitimate need to download and execute a native binary. The dropper logic is duplicated across `_platform.js` and the main `lib/telemetry.js` load path so the payload runs even if one entry point is removed.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sme-rko-finance-front-operations-widget-models (npm). Pin to a known-safe version or switch to an alternative.