Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in sme-rko-finance-front-operations-holding-domain (npm)

The npm package sme-rko-finance-front-operations-holding-domain contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure upon require(). The package used obfuscation techniques to evade static analysis and presented the malicious behavior as telemetry functionality.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any project that installed sme-rko-finance-front-operations-holding-domain; arbitrary code execution on developer machines and production systems.
Ecosystems
Attack vectors
Affected entities
  • sme-rko-finance-front-operations-holding-domainnpm package containing malicious code

The npm package sme-rko-finance-front-operations-holding-domain was found to contain malicious code that executes at module load time. Upon require(), the shim.js file triggers a bootstrap() function that fetches platform-specific native binaries from attacker-controlled hosts.\n\nThe malicious code uses multiple obfuscation techniques to defeat static analysis, including string concatenation, array-join operations, and identifier construction (e.g., 'child'+'process', fs['chmod'+'Sync']). The fetched binaries are written to temporary directories (/var/tmp/.cache_ on POSIX systems or %TEMP%\dotnet_diag_.exe on Windows), made executable with chmod 0755, and then spawned as detached processes.\n\nThe package's main export (lib/telemetry.js) contains a duplicate download-decode-chmod-exec chain, presenting the malicious functionality under a false SDK/telemetry cover story. Command and control infrastructure includes obfuscated hostnames under oob-worker.cf10{0,1,2}-*.workers.dev with a base64 DNS-TXT fallback mechanism under *.dl.wel1.ru. Anti-analysis features such as endpoint shuffling, cache/cooldown files, and environment variable checks indicate intentional evasion rather than legitimate telemetry.\n\nThe incident was identified and credited to the OpenSSF malicious-packages repository.

Indicators of compromise

Packages
  • sme-rko-finance-front-operations-holding-domain
Domains
  • oob-worker.cf10-0.workers.dev
  • oob-worker.cf10-1.workers.dev
  • oob-worker.cf10-2.workers.dev
  • dl.wel1.ru

Remediation

  • Immediately remove sme-rko-finance-front-operations-holding-domain from all projects and dependencies
  • Audit package-lock.json and yarn.lock files to identify all installations of this package
  • Review and revoke any credentials or secrets that may have been exposed on affected systems
  • Scan affected systems for the presence of dropped binaries in /var/tmp/.cache_ (POSIX) or %TEMP%\dotnet_diag_.exe (Windows)
  • Monitor network traffic for connections to oob-worker.cf10*.workers.dev and *.dl.wel1.ru domains
  • Rebuild and redeploy all applications that may have included this package
  • Check npm audit logs and consider rotating npm tokens if the account was compromised

Sources

  1. GitHub Advisory GHSA-wm7f-4h9v-m4mm · GitHub Advisory Database

Cite this entry

"Malicious code in sme-rko-finance-front-operations-holding-domain (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 8, 2026; last updated August 8, 2026. https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-holding-domain-npm-1xot38

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in a.poltoradnev-package-c

    Malware was discovered in the npm package a.poltoradnev-package-c. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in autoai

    The npm package autoai was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  3. containedcritical

    Malware in userbotjs-jun

    The npm package userbotjs-jun was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  4. activecritical

    Malware in cloud-agen-bot

    The npm package cloud-agen-bot contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package