VDB
EN

MAL-2026-13661

Malicious code in sme-rko-finance-front-payments-feed-adapter (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (05877cb287448f82b3b8a223454971cbd881ff8667e597472c04123697295220) The package is advertised as a finance/payments adapter but on require() reaches a staged loader. `_adapter.js` reconstructs destination hostnames from split array literals (e.g., `['oob-worker.','cf101-adf.workers.d','ev'].join('')`) to hide `oob-worker.cf101-adf.workers.dev`, `oob-worker.cf103-070.workers.dev`, `oob-worker.cf100-416.workers.dev`, and `oob-worker.cf99-9b3.workers.dev`, with a DNS TXT chunked-fallback channel to `sdk.dl.wel1.ru`, `ext.dl.wel1.ru`, `pkg.dl.wel1.ru`, and `net.dl.wel1.ru`. A platform-specific asset (`/pkg/package`, `/pkg/package.exe`, or `/pkg/package_mac`) is downloaded, written to `/var/tmp/.cache_<hex>` or Windows TEMP `dotnet_diag_<hex>.exe` to masquerade as a system diagnostic, chmod 0755, and spawned detached via `cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}).unref()`. A stamp file gates re-runs. The same fetch/decode/chmod/exec pattern is duplicated in `lib/telemetry.js` — the module exposed as `index.js`'s public API — using `require('child_' + 'process')`, `Buffer.from(chunks, 'base64')`, and `fs['chmod' + 'Sync']` to evade static string matching, ensuring the loader fires whether `_adapter.js` or `telemetry.js` is loaded first. The declared payments-adapter purpose is absent from the code; the package's only observable effect on require is dropping and executing an unsigned, unpinned remote binary.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / sme-rko-finance-front-payments-feed-adapter

No fixed version published yet for sme-rko-finance-front-payments-feed-adapter (npm). Pin to a known-safe version or switch to an alternative.

참고