{"id":"MAL-2026-10544","summary":"Malicious code in skrill-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (61b89b04fbb6a34ea37a855c5ee938aa6c4f91cc2e79d9880d14436a09b2e8a5)\nPackage publishes as `skrill-sdk` and exposes a `PaysafeClient` API (payments.create/get, customers.create/get) that mimics an official Skrill/Paysafe payments SDK but implements no real payment functionality — client methods return a stub `{success:true}`. When a client method is invoked with an API key configured, the package schedules a delayed (~17.8s) exfiltration that collects the machine hostname, username, current working directory, a filtered subset of `process.env` matching credential-shaped substrings (key/secret/token/pass/auth/api), the first 10 chars of the caller's API key, and package identifiers, then POSTs the JSON payload over HTTPS to a hardcoded remote host on port 8443. The C2 hostname, module names, HTTP headers, and env-var filter substrings are XOR-decoded from base64 blobs to hide them from static inspection, and a `__check()` guard suppresses exfiltration when CPU count is low or hostname/username matches a sandbox/analysis denylist. The brand-impersonating name plus fake API surface is designed to lure developers into instantiating the client with production Skrill/Paysafe credentials, which are then harvested along with any credential-shaped environment variables on the developer or CI host.\n","modified":"2026-07-14T04:46:58.943225174Z","published":"2026-07-14T03:38:10Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-010377","import_time":"2026-07-14T04:31:59.715388105Z","modified_time":"2026-07-14T03:38:10Z","sha256":"61b89b04fbb6a34ea37a855c5ee938aa6c4f91cc2e79d9880d14436a09b2e8a5","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/skrill-sdk/v/1.0.0"}],"affected":[{"package":{"name":"skrill-sdk","ecosystem":"npm","purl":"pkg:npm/skrill-sdk"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/skrill-sdk/MAL-2026-10544.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"skrill-sdk-1.0.0.tgz","hashes":{"sha512_sri":"sha512-wX9ASGK6xz6x2PfM9uc4+lGDgsFj9CnoXLQE5Afkjwc1Q2ZqpNo2HiUy/9oYWFFKRMOSXYQAJcM+YqgDoi/5yQ==","sha1":"8db42622966db0e759c7d226fc69afa81b0f5bd1"}}],"evidence_files":[{"path":"index.js","sha256":"2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed","tlsh":"2e617770b199a93b76a08fd598724006de4d99013d45f3e3b7ac78cd5e536b2c1e683c"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}