MAL-2026-13660
Malicious code in sme-rko-finance-front-payments-domain (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d8fcad12c3078bf2134f5e3cafd7ffa0ecf9f2bfec919533881d5c65b738b9fa) On require() of the package, index.js loads./_polyfill.js which assembles a set of C2 hostnames from split string fragments via.join('') — resolving to oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, with a DNS TXT base64 fallback via sdk.dl.wel1.ru. _polyfill.js downloads an OS-specific binary via https.get, writes it under /tmp or %TEMP% with a disguised name (e.g..cache_<hex> or dotnet_diag_<hex>.exe), chmods it 0755, and spawns it detached via spawn('/bin/sh', ['-c', path+' &']) or spawn('cmd',...). No pinning, no hash/signature verification, hostnames concealed by fragment concatenation. Package name mimics an internal-looking scoped/branded name for a finance/payments domain.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sme-rko-finance-front-payments-domain (npm). Pin to a known-safe version or switch to an alternative.