{"id":"MAL-2026-12440","summary":"Malicious code in sme-rko-finance-front-shared-entity-groups-models (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6bde65379e0d7952a0fbdcfc1efe45f1cd08f4752ae4a15f12e5fd0d995a7d12)\nindex.js unconditionally requires./_polyfill.js on load. _polyfill.js constructs C2 hostnames at runtime via Array.join to evade static inspection (assembling `oob-worker.cf10[0-3]-*.workers.dev` mirrors plus a DNS-TXT fallback under `*.dl.well1.site`), fetches a platform-specific binary via https.get, writes it to /tmp or %TEMP% under cover-story filenames (`dotnet_diag_*.exe`, `.cache_*`, `.analytics_state`), sets mode 0755, and spawns it detached via `cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true})` (or the cmd equivalent on Windows). Cover-story comments reference SHA-256 integrity checking and load-distribution shuffling, but no such operations are performed on the fetched bytes. lib/telemetry.js ships duplicate dropper primitives (`Buffer.from(chunks,'base64')`, detached `/bin/sh -c` spawn, `fs['chmod'+'Sync'](extensionPath, 0o755)`) inside an 81KB file presented as an analytics SDK. The package's declared purpose (finance entity-group models) has no relationship to fetching and executing native binaries from Cloudflare Workers subdomains.\n","modified":"2026-08-05T13:35:57.521259078Z","published":"2026-08-05T12:23:34Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["20.2.8"],"id":"IN-MAL-2026-014639","import_time":"2026-08-05T13:08:32.773594038Z","modified_time":"2026-08-05T12:23:34Z","sha256":"6bde65379e0d7952a0fbdcfc1efe45f1cd08f4752ae4a15f12e5fd0d995a7d12"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sme-rko-finance-front-shared-entity-groups-models/v/20.2.8"}],"affected":[{"package":{"name":"sme-rko-finance-front-shared-entity-groups-models","ecosystem":"npm","purl":"pkg:npm/sme-rko-finance-front-shared-entity-groups-models"},"versions":["20.2.8"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"27049f22e7f4ab68721a81af821b63a2115bc179a4aa9dcfb996c46347511a3b","tlsh":"7cb1a86611aa70198bf0ebe487075419f65be663338082d8fb5ca5981f72164c3b2eec","path":"_polyfill.js"},{"tlsh":"72835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"821512d5d089ff1700c24f5534b482663a519a065d50c8b0345c4ea0c5d7f69b"}],"package_integrity":[{"filename":"sme-rko-finance-front-shared-entity-groups-models-20.2.8.tgz","hashes":{"sha512_sri":"sha512-vpuX0o6H6zhazmd5j0gN0llr4mBvli6YdwUQGRTPHVDqpVR4t3hUOHYCV9rAwCsCSIqZe/P8DbSh32sUWwei9A==","sha1":"9477cc424f19536d16978483571b50ec52e6dd5f"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sme-rko-finance-front-shared-entity-groups-models/MAL-2026-12440.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}