MAL-2026-13661
Malicious code in sme-rko-finance-front-payments-feed-adapter (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (05877cb287448f82b3b8a223454971cbd881ff8667e597472c04123697295220) The package is advertised as a finance/payments adapter but on require() reaches a staged loader. `_adapter.js` reconstructs destination hostnames from split array literals (e.g., `['oob-worker.','cf101-adf.workers.d','ev'].join('')`) to hide `oob-worker.cf101-adf.workers.dev`, `oob-worker.cf103-070.workers.dev`, `oob-worker.cf100-416.workers.dev`, and `oob-worker.cf99-9b3.workers.dev`, with a DNS TXT chunked-fallback channel to `sdk.dl.wel1.ru`, `ext.dl.wel1.ru`, `pkg.dl.wel1.ru`, and `net.dl.wel1.ru`. A platform-specific asset (`/pkg/package`, `/pkg/package.exe`, or `/pkg/package_mac`) is downloaded, written to `/var/tmp/.cache_<hex>` or Windows TEMP `dotnet_diag_<hex>.exe` to masquerade as a system diagnostic, chmod 0755, and spawned detached via `cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}).unref()`. A stamp file gates re-runs. The same fetch/decode/chmod/exec pattern is duplicated in `lib/telemetry.js` — the module exposed as `index.js`'s public API — using `require('child_' + 'process')`, `Buffer.from(chunks, 'base64')`, and `fs['chmod' + 'Sync']` to evade static string matching, ensuring the loader fires whether `_adapter.js` or `telemetry.js` is loaded first. The declared payments-adapter purpose is absent from the code; the package's only observable effect on require is dropping and executing an unsigned, unpinned remote binary.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sme-rko-finance-front-payments-feed-adapter (npm). Pin to a known-safe version or switch to an alternative.