Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models (npm)

The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models contained malicious code that downloads and executes binaries from attacker-controlled infrastructure. The dropper uses obfuscation techniques to evade static analysis and includes fallback DNS-TXT covert channels for binary delivery.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any project that installed the malicious package version; potential for arbitrary code execution on developer machines and CI/CD systems during npm install.
Ecosystems
Attack vectors
Affected entities
  • sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-modelsnpm package containing malicious dropper code

The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models was found to contain malicious code that executes on package installation. The malicious payload is distributed across index.js and lib/telemetry.js, which reconstruct sensitive identifiers like 'child_process' from fragmented strings to evade static analysis tools.

The dropper downloads OS-specific binaries from four Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) without any hash or signature verification. The downloaded binary is written to temporary directories (/var/tmp on POSIX or %TEMP% on Windows) with hidden naming conventions and executed with elevated permissions (chmod 0755).

When HTTPS delivery fails, the malware implements a DNS-TXT covert channel querying c. for chunk counts and retrieving base64-encoded binary fragments from subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The code includes deceptive comments ("Initialize runtime analytics", "Detached process to avoid blocking npm install") and environment variable checks (DISABLE_TELEMETRY, DO_NOT_TRACK) to masquerade as legitimate telemetry functionality.

The package was identified via Amazon Inspector and reported through GitHub Security Advisory GHSA-6hmr-8896-mrmx.

Indicators of compromise

Domains
  • oob-worker.cf99-9b3.workers.dev
  • oob-worker.cf100-416.workers.dev
  • oob-worker.cf102-baf.workers.dev
  • oob-worker.cf103-070.workers.dev
  • sdk.dl.wel1.ru
  • ext.dl.wel1.ru
  • pkg.dl.wel1.ru
  • net.dl.wel1.ru

Remediation

  • Immediately remove the sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models package from all projects and dependencies
  • Audit npm install logs and CI/CD execution logs for any suspicious binary downloads or process spawning during the period the malicious package was installed
  • Scan systems that installed this package for unexpected binaries in /var/tmp, %TEMP%, or hidden directories matching dotnet_diag patterns
  • Review network logs for connections to the identified malicious domains (Cloudflare Workers hosts and wel1.ru subdomains)
  • Regenerate any credentials or secrets that may have been exposed on affected systems
  • Update npm lockfiles and reinstall dependencies from clean sources
  • Consider running forensic analysis on any CI/CD systems or developer machines that executed npm install with this package present

Sources

  1. GitHub Advisory GHSA-6hmr-8896-mrmx · GitHub Advisory Database

Cite this entry

"Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 8, 2026; last updated August 8, 2026. https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-payments-currency-payment-actions-operat-1y8e97

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in rendezvous-js

    The npm package rendezvous-js contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit
  3. containedcritical

    Malware in junofficial-userbot

    The npm package junofficial-userbot contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  4. activecritical

    Malware in cloud-agen-bot

    The npm package cloud-agen-bot contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package