Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl (npm)

The npm package sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl contained malicious code that executes remote code on require(). The package downloads platform-specific executables from obfuscated Cloudflare Workers domains or DNS-TXT fallback resolvers and executes them with elevated privileges.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any project that installed sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl; remote code execution on require()
Ecosystems
Attack vectors
Affected entities
  • sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-implnpm package containing malicious code

The npm package sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl was found to contain malicious code that triggers on package import. The package's index.js loads a _bootstrap.js module that selects a payload path based on the operating system and architecture (linux_x64, linux_arm64, darwin, win32).\n\nThe malicious code downloads an executable over HTTPS from one of several Cloudflare Workers subdomains (oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev) whose hostnames are assembled at runtime using array-join obfuscation. If the primary download fails, it falls back to DNS-TXT record lookups across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru.\n\nThe downloaded executable is written to /var/tmp (Linux/macOS) or %TEMP% (Windows) under a disguised filename, given execute permissions (chmod 755), and spawned as a detached process via /bin/sh -c or cmd.exe. The package.json falsely describes the module as an "API client wrappers" for an internal payments module, masking the actual malicious behavior.\n\nThe use of hostname obfuscation via array-join and DNS-TXT fallback resolution indicates deliberate evasion of static string-based security scanners. The incident was identified and credited to the OpenSSF malicious-packages project.

Indicators of compromise

Packages
  • sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl
Domains
  • oob-worker.cf101-adf.workers.dev
  • oob-worker.cf103-070.workers.dev
  • oob-worker.cf99-9b3.workers.dev
  • oob-worker.cf102-baf.workers.dev
  • sdk.dl.wel1.ru
  • ext.dl.wel1.ru
  • pkg.dl.wel1.ru
  • net.dl.wel1.ru

Remediation

  • Immediately remove sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl from all projects and dependencies
  • Audit package-lock.json and yarn.lock files to identify all installations of this package
  • Review npm audit logs and CI/CD logs for any suspicious activity or unexpected process execution during the period this package was installed
  • Regenerate any credentials, API keys, or secrets that may have been exposed on systems where this package was installed
  • Scan affected systems for the presence of downloaded executables in /var/tmp, %TEMP%, or other temporary directories
  • Monitor network traffic for connections to the identified Cloudflare Workers domains and wel1.ru DNS records
  • Update to a clean version of any legitimate package this was impersonating, if applicable

Sources

  1. GitHub Advisory GHSA-8q7h-xvgq-ff27 · GitHub Advisory Database

Cite this entry

"Malicious code in sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 8, 2026; last updated August 8, 2026. https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-payments-classic-payment-actions-operati-1mgzvt

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in epic-common-node (npm)

    The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.

    npmCompromised package
  2. containedcritical

    Malware in @siwatfa/yorn

    Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  3. activecritical

    Malware in @zizie071/libsignal-node

    The npm package @zizie071/libsignal-node contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  4. resolvedcritical

    Malicious code in epic-sso (npm)

    The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package