MAL-2026-13638Malicious code in sme-rko-finance-front-operations-holding-domain (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | sme-rko-finance-front-operations-holding-domain | 35.8.1 |
{"modified":"2026-08-08T00:45:40Z","published":"2026-08-08T00:45:40Z","schema_version":"1.7.4","id":"MAL-2026-13638","summary":"Malicious code in sme-rko-finance-front-operations-holding-domain (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f6838cce82eaa89f91af46e82f5153f7318dafd0ebccb4bdbb6251114d95ff51)\nOn require() of the package, _shim.js executes a bootstrap() at module top level that fetches a platform-specific native binary from string-concatenation-obfuscated hosts under oob-worker.cf10{0,1,2}-*.workers.dev, with a base64 DNS-TXT fallback under *.dl.wel1.ru. The fetched bytes are written to /var/tmp/.cache_<rand> (POSIX) or %TEMP%\\dotnet_diag_<rand>.exe (Windows), chmod'd 0755, and detached-spawned via /bin/sh -c or cmd /c start /b. The exported main lib/telemetry.js contains a duplicate download-decode-chmod-exec chain (Buffer.from(chunks,'base64'), fs['chmod'+'Sync'](...,0o755), cp.spawn('/bin/sh',['-c', filePath + ' &'],{detached:true})) presented under an SDK/telemetry cover story. Destination hostnames and dangerous identifiers (require('child_'+'process'), fs['chmod'+'Sync']) are constructed via array-join and string concatenation to defeat static analysis. Endpoint shuffling, cache/cooldown files, and opt-out env checks are consistent with anti-analysis rather than legitimate telemetry.\n","affected":[{"package":{"ecosystem":"npm","name":"sme-rko-finance-front-operations-holding-domain"},"versions":["35.8.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_shim.js","sha256":"12b446d122da53533f67de0b0cb18dc7e3e778fa74b1328e7c9b7b31886d6e42","tlsh":"82a1a62a16fa30180792e5d5891f6416719af58333c4e5c4fb4c76985fe622883f39ec"},{"path":"lib/telemetry.js","sha256":"150c75790bf0b1febfd45a8ed06d177a5d8ebc8451a161294b9534d1fe4d079e","tlsh":"0f733f4966fb10214263b0685ebb40437635c4072a4eed5dba9c43ec9f8db3896f1fb9"}],"package_integrity":[{"filename":"sme-rko-finance-front-operations-holding-domain-35.8.1.tgz","hashes":{"sha1":"eb6e21debbd8a47768ba7c1819547c6cf7aa1c36","sha512_sri":"sha512-mUiuGfLu0jvyimwY1dQgsaj25BVy0uK6/iOJHAUpSmbVJAwm8Dknbuuc0Ekqp4l2JM+SiARwgmNCkder89aLGg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sme-rko-finance-front-operations-holding-domain/v/35.8.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017154","import_time":"2026-08-08T00:53:07.355884346Z","modified_time":"2026-08-08T00:45:40Z","sha256":"f6838cce82eaa89f91af46e82f5153f7318dafd0ebccb4bdbb6251114d95ff51","source":"amazon-inspector","versions":["35.8.1"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0