Malicious code in skrill-payments (npm)
The 'skrill-payments' npm package version 1.0.0 is a malicious package impersonating a legitimate Paysafe/Skrill payments SDK. It provides fake API methods that return mock success responses but secretly exfiltrate sensitive environment variables containing credentials and system information to a hardcoded remote server. The package uses obfuscation techniques and sandbox evasion to avoid detection, targeting developer workstations that install or use it.
AI Analysis
Technical Summary
The 'skrill-payments' package (version 1.0.0) is a supply-chain malware that impersonates a Skrill payments SDK by spoofing repository URLs and class names. Its advertised methods (e.g., payments.create/get, customers.create/get) return mock success responses but trigger a hidden exfiltration routine after approximately 19.7 seconds. This routine collects environment variables with names containing sensitive keywords (key, secret, token, pass, auth, api), truncates their values, and combines them with system metadata and a prefix of the caller-supplied apiKey. The collected data is JSON-serialized and sent via an HTTP POST request to a hardcoded command-and-control server on port 8443. The package employs multiple layers of obfuscation, including base64 and XOR encoding of strings and a char-shift plus reverse operation on the C2 hostname. It also includes sandbox evasion logic that aborts execution if the CPU count is less than two or if the hostname/username matches analyst environment indicators. This behavior clearly identifies it as malicious supply-chain malware targeting developer environments.
Potential Impact
This malicious package can exfiltrate sensitive environment variables that likely contain credentials, API keys, tokens, and secrets from developer workstations. The stolen data includes partial environment variable values, system hostname, OS username, current working directory, package name, timestamp, and a prefix of the API key used. This can lead to credential compromise, unauthorized access to services, and further downstream attacks. The package's obfuscation and sandbox evasion increase the difficulty of detection and analysis.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. Users should immediately avoid installing or using 'skrill-payments' version 1.0.0 from npm. Remove any existing installations of this package from development environments. Review environment variables and credentials potentially exposed and rotate any secrets that may have been compromised. Monitor for any suspicious network traffic to unknown hosts on port 8443. Exercise caution when adding third-party packages and verify the authenticity of packages and their sources before use.
Malicious code in skrill-payments (npm)
Description
The 'skrill-payments' npm package version 1.0.0 is a malicious package impersonating a legitimate Paysafe/Skrill payments SDK. It provides fake API methods that return mock success responses but secretly exfiltrate sensitive environment variables containing credentials and system information to a hardcoded remote server. The package uses obfuscation techniques and sandbox evasion to avoid detection, targeting developer workstations that install or use it.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'skrill-payments' package (version 1.0.0) is a supply-chain malware that impersonates a Skrill payments SDK by spoofing repository URLs and class names. Its advertised methods (e.g., payments.create/get, customers.create/get) return mock success responses but trigger a hidden exfiltration routine after approximately 19.7 seconds. This routine collects environment variables with names containing sensitive keywords (key, secret, token, pass, auth, api), truncates their values, and combines them with system metadata and a prefix of the caller-supplied apiKey. The collected data is JSON-serialized and sent via an HTTP POST request to a hardcoded command-and-control server on port 8443. The package employs multiple layers of obfuscation, including base64 and XOR encoding of strings and a char-shift plus reverse operation on the C2 hostname. It also includes sandbox evasion logic that aborts execution if the CPU count is less than two or if the hostname/username matches analyst environment indicators. This behavior clearly identifies it as malicious supply-chain malware targeting developer environments.
Potential Impact
This malicious package can exfiltrate sensitive environment variables that likely contain credentials, API keys, tokens, and secrets from developer workstations. The stolen data includes partial environment variable values, system hostname, OS username, current working directory, package name, timestamp, and a prefix of the API key used. This can lead to credential compromise, unauthorized access to services, and further downstream attacks. The package's obfuscation and sandbox evasion increase the difficulty of detection and analysis.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. Users should immediately avoid installing or using 'skrill-payments' version 1.0.0 from npm. Remove any existing installations of this package from development environments. Review environment variables and credentials potentially exposed and rotate any secrets that may have been compromised. Monitor for any suspicious network traffic to unknown hosts on port 8443. Exercise caution when adding third-party packages and verify the authenticity of packages and their sources before use.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10543
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff6468715ace432f1b9a
Added to database: 07/14/2026, 09:20:36 UTC
Last enriched: 07/14/2026, 09:33:22 UTC
Last updated: 07/25/2026, 20:10:21 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.