Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models (npm)
The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models contained malicious code that downloads and executes binaries from attacker-controlled infrastructure. The dropper uses obfuscation techniques to evade static analysis and includes fallback DNS-TXT covert channels for binary delivery.
- Disclosed
- Last updated
- Blast radius
- Any project that installed the malicious package version; potential for arbitrary code execution on developer machines and CI/CD systems during npm install.
- Ecosystems
- Attack vectors
- Affected entities
- sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-modelsnpm package containing malicious dropper code
The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models was found to contain malicious code that executes on package installation. The malicious payload is distributed across index.js and lib/telemetry.js, which reconstruct sensitive identifiers like 'child_process' from fragmented strings to evade static analysis tools.
The dropper downloads OS-specific binaries from four Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) without any hash or signature verification. The downloaded binary is written to temporary directories (/var/tmp on POSIX or %TEMP% on Windows) with hidden naming conventions and executed with elevated permissions (chmod 0755).
When HTTPS delivery fails, the malware implements a DNS-TXT covert channel querying c. for chunk counts and retrieving base64-encoded binary fragments from subdomains under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The code includes deceptive comments ("Initialize runtime analytics", "Detached process to avoid blocking npm install") and environment variable checks (DISABLE_TELEMETRY, DO_NOT_TRACK) to masquerade as legitimate telemetry functionality.
The package was identified via Amazon Inspector and reported through GitHub Security Advisory GHSA-6hmr-8896-mrmx.
Indicators of compromise
- Domains
- oob-worker.cf99-9b3.workers.dev
- oob-worker.cf100-416.workers.dev
- oob-worker.cf102-baf.workers.dev
- oob-worker.cf103-070.workers.dev
- sdk.dl.wel1.ru
- ext.dl.wel1.ru
- pkg.dl.wel1.ru
- net.dl.wel1.ru
Remediation
- Immediately remove the sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models package from all projects and dependencies
- Audit npm install logs and CI/CD execution logs for any suspicious binary downloads or process spawning during the period the malicious package was installed
- Scan systems that installed this package for unexpected binaries in /var/tmp, %TEMP%, or hidden directories matching dotnet_diag patterns
- Review network logs for connections to the identified malicious domains (Cloudflare Workers hosts and wel1.ru subdomains)
- Regenerate any credentials or secrets that may have been exposed on affected systems
- Update npm lockfiles and reinstall dependencies from clean sources
- Consider running forensic analysis on any CI/CD systems or developer machines that executed npm install with this package present
Sources
- GitHub Advisory GHSA-6hmr-8896-mrmx · GitHub Advisory Database
Cite this entry
"Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 8, 2026; last updated August 8, 2026. https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-payments-currency-payment-actions-operat-1y8e97
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in rendezvous-js
The npm package rendezvous-js contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit - containedcritical
Malware in junofficial-userbot
The npm package junofficial-userbot contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.
npmCompromised package - activecritical
Malware in cloud-agen-bot
The npm package cloud-agen-bot contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package