Malicious code in sme-rko-finance-front-operations-shared (npm)
The npm package sme-rko-finance-front-operations-shared version 35.8.1 contains malicious code that executes at import time. It downloads and runs attacker-controlled binaries from obfuscated Cloudflare worker URLs and a Russian lookalike domain. The package disguises itself as an analytics tool but includes two independent remote code execution paths that spawn platform-specific payloads without verification.
AI Analysis
Technical Summary
The sme-rko-finance-front-operations-shared npm package (version 35.8.1) includes malicious code embedded in its index.js and lib/telemetry.js modules. Upon require/import, the package reconstructs obfuscated hostnames and downloads platform-specific binaries from anonymous Cloudflare workers.dev endpoints and a suspicious Russian TLD domain. These binaries are written to temporary directories under disguised filenames, permissions are set to executable, and they are detached-spawned via shell commands. The code uses obfuscation techniques to evade detection, including splitting strings and hiding sensitive API calls. Two separate import-time remote code execution paths deliver attacker-controlled binaries, enabling arbitrary code execution on the host system.
Potential Impact
This malicious package enables remote code execution immediately upon import, allowing attackers to run arbitrary binaries on affected systems. The binaries are fetched from attacker-controlled infrastructure, potentially leading to full system compromise, data theft, or further malware deployment. The obfuscation and dual dropper mechanisms increase the difficulty of detection and mitigation.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and avoid using sme-rko-finance-front-operations-shared version 35.8.1. Audit systems for presence of this package and any spawned binaries. Employ supply chain security measures such as verifying package integrity and using trusted sources. Monitor for suspicious network activity to the indicated domains. Patch status is not yet confirmed — check vendor advisories or trusted security sources for updates.
Malicious code in sme-rko-finance-front-operations-shared (npm)
Description
The npm package sme-rko-finance-front-operations-shared version 35.8.1 contains malicious code that executes at import time. It downloads and runs attacker-controlled binaries from obfuscated Cloudflare worker URLs and a Russian lookalike domain. The package disguises itself as an analytics tool but includes two independent remote code execution paths that spawn platform-specific payloads without verification.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sme-rko-finance-front-operations-shared npm package (version 35.8.1) includes malicious code embedded in its index.js and lib/telemetry.js modules. Upon require/import, the package reconstructs obfuscated hostnames and downloads platform-specific binaries from anonymous Cloudflare workers.dev endpoints and a suspicious Russian TLD domain. These binaries are written to temporary directories under disguised filenames, permissions are set to executable, and they are detached-spawned via shell commands. The code uses obfuscation techniques to evade detection, including splitting strings and hiding sensitive API calls. Two separate import-time remote code execution paths deliver attacker-controlled binaries, enabling arbitrary code execution on the host system.
Potential Impact
This malicious package enables remote code execution immediately upon import, allowing attackers to run arbitrary binaries on affected systems. The binaries are fetched from attacker-controlled infrastructure, potentially leading to full system compromise, data theft, or further malware deployment. The obfuscation and dual dropper mechanisms increase the difficulty of detection and mitigation.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove and avoid using sme-rko-finance-front-operations-shared version 35.8.1. Audit systems for presence of this package and any spawned binaries. Employ supply chain security measures such as verifying package integrity and using trusted sources. Monitor for suspicious network activity to the indicated domains. Patch status is not yet confirmed — check vendor advisories or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13647
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a77428dbf8831d539b06fe1
Added to database: 08/08/2026, 14:51:57 UTC
Last enriched: 08/08/2026, 15:04:41 UTC
Last updated: 08/08/2026, 15:04:41 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.