MAL-2026-13663
Malicious code in sme-rko-finance-front-payments-feed-display-list-impl (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4e33cae8840b73256d5d48935bfa7b8490ea7a36d56edeff8adfc4ca19dfea49) On require(), index.js loads _helpers.js which selects a platform-specific endpoint, downloads a binary from one of three string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev), writes it to a hidden path (/tmp/.cache_<rand> or %TEMP%\dotnet_diag_<rand>.exe), chmods 0755, and spawns it detached with stdio ignored via cp.spawn("/bin/sh", ["-c", filePath + " &"], {detached:true, stdio:"ignore"}).unref(). A secondary fetch-and-execute path in lib/telemetry.js (loaded from index.js) duplicates the same logic with base64 chunked payload assembly, cp.spawn of the downloaded file, and fs["chmod"+"Sync"] with 0755. A DNS TXT chunked-base64 fallback resolves *.dl.wel1.ru subdomains to reconstruct the payload or endpoint when direct HTTPS is unavailable. Hostnames, the child_process module name, and the chmodSync API are all assembled via array.join / string concatenation to evade static analysis, and cache filenames (.analytics_state, dotnet_diag_*.exe) are chosen to blend in. The package's stated purpose is an API client wrapper, which does not require fetching or executing native binaries.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sme-rko-finance-front-payments-feed-display-list-impl (npm). Pin to a known-safe version or switch to an alternative.