VYPR

npm · Malicious package advisory

Malware

sme-rko-finance-front-payments-feed-adapter

GHSA-xprg-ffr4-2rw4

Malicious code in sme-rko-finance-front-payments-feed-adapter (npm)

Details

**Severity:** Critical

**Affected versions:** `= 35.8.1`

## Source: amazon-inspector (05877cb287448f82b3b8a223454971cbd881ff8667e597472c04123697295220)
The package is advertised as a finance/payments adapter but on require() reaches a staged loader. `_adapter.js` reconstructs destination hostnames from split array literals (e.g., `['oob-worker.','cf101-adf.workers.d','ev'].join('')`) to hide `oob-worker.cf101-adf.workers.dev`, `oob-worker.cf103-070.workers.dev`, `oob-worker.cf100-416.workers.dev`, and `oob-worker.cf99-9b3.workers.dev`, with a DNS TXT chunked-fallback channel to `sdk.dl.wel1.ru`, `ext.dl.wel1.ru`, `pkg.dl.wel1.ru`, and `net.dl.wel1.ru`. A platform-specific asset (`/pkg/package`, `/pkg/package.exe`, or `/pkg/package_mac`) is downloaded, written to `/var/tmp/.cache_<hex>` or Windows TEMP `dotnet_diag_<hex>.exe` to masquerade as a system diagnostic, chmod 0755, and spawned detached via `cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}).unref()`. A stamp file gates re-runs. The same fetch/decode/chmod/exec pattern is duplicated in `lib/telemetry.js` — the module exposed as `index.js`'s public API — using `require('child_' + 'process')`, `Buffer.from(chunks, 'base64')`, and `fs['chmod' + 'Sync']` to evade static string matching, ensuring the loader fires whether `_adapter.js` or `telemetry.js` is loaded first. The declared payments-adapter purpose is absent from the code; the package's only observable effect on require is dropping and executing an unsigned, unpinned remote binary.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/f4865d38bdd8cf89a75895cd20168baaaa03aea4/osv/malicious/npm/sme-rko-finance-front-payments-feed-adapter/MAL-2026-13661.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/f4865d38bdd8cf89a75895cd20168baaaa03aea4/osv/malicious/npm/sme-rko-finance-front-payments-feed-adapter/MAL-2026-13661.json
- https://www.npmjs.com/package/sme-rko-finance-front-payments-feed-adapter/v/35.8.1
- https://github.com/advisories/GHSA-xprg-ffr4-2rw4

Compromised versions (1)

  • = 35.8.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.