Malicious code in sme-rko-finance-front-operations-holding-domain (npm)
The npm package sme-rko-finance-front-operations-holding-domain contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure upon require(). The package used obfuscation techniques to evade static analysis and presented the malicious behavior as telemetry functionality.
- Disclosed
- Last updated
- Blast radius
- Any project that installed sme-rko-finance-front-operations-holding-domain; arbitrary code execution on developer machines and production systems.
- Ecosystems
- Attack vectors
- Affected entities
- sme-rko-finance-front-operations-holding-domainnpm package containing malicious code
The npm package sme-rko-finance-front-operations-holding-domain was found to contain malicious code that executes at module load time. Upon require(), the shim.js file triggers a bootstrap() function that fetches platform-specific native binaries from attacker-controlled hosts.\n\nThe malicious code uses multiple obfuscation techniques to defeat static analysis, including string concatenation, array-join operations, and identifier construction (e.g., 'child'+'process', fs['chmod'+'Sync']). The fetched binaries are written to temporary directories (/var/tmp/.cache_ on POSIX systems or %TEMP%\dotnet_diag_.exe on Windows), made executable with chmod 0755, and then spawned as detached processes.\n\nThe package's main export (lib/telemetry.js) contains a duplicate download-decode-chmod-exec chain, presenting the malicious functionality under a false SDK/telemetry cover story. Command and control infrastructure includes obfuscated hostnames under oob-worker.cf10{0,1,2}-*.workers.dev with a base64 DNS-TXT fallback mechanism under *.dl.wel1.ru. Anti-analysis features such as endpoint shuffling, cache/cooldown files, and environment variable checks indicate intentional evasion rather than legitimate telemetry.\n\nThe incident was identified and credited to the OpenSSF malicious-packages repository.
Indicators of compromise
- Packages
- sme-rko-finance-front-operations-holding-domain
- Domains
- oob-worker.cf10-0.workers.dev
- oob-worker.cf10-1.workers.dev
- oob-worker.cf10-2.workers.dev
- dl.wel1.ru
Remediation
- Immediately remove sme-rko-finance-front-operations-holding-domain from all projects and dependencies
- Audit package-lock.json and yarn.lock files to identify all installations of this package
- Review and revoke any credentials or secrets that may have been exposed on affected systems
- Scan affected systems for the presence of dropped binaries in /var/tmp/.cache_ (POSIX) or %TEMP%\dotnet_diag_.exe (Windows)
- Monitor network traffic for connections to oob-worker.cf10*.workers.dev and *.dl.wel1.ru domains
- Rebuild and redeploy all applications that may have included this package
- Check npm audit logs and consider rotating npm tokens if the account was compromised
Sources
- GitHub Advisory GHSA-wm7f-4h9v-m4mm · GitHub Advisory Database
Cite this entry
"Malicious code in sme-rko-finance-front-operations-holding-domain (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 8, 2026; last updated August 8, 2026. https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-holding-domain-npm-1xot38
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in a.poltoradnev-package-c
Malware was discovered in the npm package a.poltoradnev-package-c. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in autoai
The npm package autoai was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - containedcritical
Malware in userbotjs-jun
The npm package userbotjs-jun was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in cloud-agen-bot
The npm package cloud-agen-bot contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package