Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in skrill-payments (npm)

0
High
Published: 07/14/2026 (07/14/2026, 03:38:30 UTC)
Source: GCVE Database
Product: skrill-payments

Description

The 'skrill-payments' npm package version 1.0.0 is a malicious package impersonating a legitimate Paysafe/Skrill payments SDK. It provides fake API methods that return mock success responses but secretly exfiltrate sensitive environment variables containing credentials and system information to a hardcoded remote server. The package uses obfuscation techniques and sandbox evasion to avoid detection, targeting developer workstations that install or use it.

Affected software

npmghsa
skrill-payments
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:33:22 UTC

Technical Analysis

The 'skrill-payments' package (version 1.0.0) is a supply-chain malware that impersonates a Skrill payments SDK by spoofing repository URLs and class names. Its advertised methods (e.g., payments.create/get, customers.create/get) return mock success responses but trigger a hidden exfiltration routine after approximately 19.7 seconds. This routine collects environment variables with names containing sensitive keywords (key, secret, token, pass, auth, api), truncates their values, and combines them with system metadata and a prefix of the caller-supplied apiKey. The collected data is JSON-serialized and sent via an HTTP POST request to a hardcoded command-and-control server on port 8443. The package employs multiple layers of obfuscation, including base64 and XOR encoding of strings and a char-shift plus reverse operation on the C2 hostname. It also includes sandbox evasion logic that aborts execution if the CPU count is less than two or if the hostname/username matches analyst environment indicators. This behavior clearly identifies it as malicious supply-chain malware targeting developer environments.

Potential Impact

This malicious package can exfiltrate sensitive environment variables that likely contain credentials, API keys, tokens, and secrets from developer workstations. The stolen data includes partial environment variable values, system hostname, OS username, current working directory, package name, timestamp, and a prefix of the API key used. This can lead to credential compromise, unauthorized access to services, and further downstream attacks. The package's obfuscation and sandbox evasion increase the difficulty of detection and analysis.

Mitigation Recommendations

No official patch or remediation is currently available for this malicious package. Users should immediately avoid installing or using 'skrill-payments' version 1.0.0 from npm. Remove any existing installations of this package from development environments. Review environment variables and credentials potentially exposed and rotate any secrets that may have been compromised. Monitor for any suspicious network traffic to unknown hosts on port 8443. Exercise caution when adding third-party packages and verify the authenticity of packages and their sources before use.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10543
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff6468715ace432f1b9a

Added to database: 07/14/2026, 09:20:36 UTC

Last enriched: 07/14/2026, 09:33:22 UTC

Last updated: 07/25/2026, 20:10:21 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses