Feed
CriticalPublished 8 Aug 2026Updated 9 Aug 202647 packages · 53 versions

GitHub Advisory npm CWE-506 sweep - 36-package 2026-08-08 batch (`sme-rko-finance-front-*` 30-package Tinkoff/T-Bank RKO SME dep-confusion cluster running WEL1DROPPER-style cross-platform Cloudflare-Workers dropper + `@coralxyz/anchor` Solana Anchor typosquat with PowerShell zip drop + `titan-exchange-shared-permissions@99.9.9` dep-confusion recon + `@rbx-ts/services` Roblox-TS typosquat catbox.moe RAT + `map-streak-kit` Linux implant with systemd persistence + `localization-fixer`/`modern-localization` jsonbin.io mutable-payload loader pair)

Summary

36 npm CWE-506 advisories 2026-08-08: 30-package sme-rko-finance-front-* Tinkoff/T-Bank RKO dep-confusion cluster (v35.8.1, WEL1DROPPER-style Cloudflare-Workers dropper) plus outliers @coralxyz/anchor Solana typosquat, titan-exchange-shared-permissions@99.9.9 recon, @rbx-ts/services, map-streak-kit Linux implant, and a localization-fixer+modern-localization jsonbin.io loader pair.

dependency-confusioncredential-theftinfostealerci-cd-compromiseobfuscationtyposquatdns-exfiltration
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · npm Security · amazon-inspector
Also known as
2026-08-08 GHSA npm batch · sme-rko-finance-front cluster · Tinkoff RKO dep-confusion · WEL1DROPPER-family dropper
Ecosystems
npm
Packages tracked
47

What happened

On 2026-08-08, the GitHub Advisory Database published 36 new npm CWE-506 (Embedded Malicious Code) advisories in the largest single-day npm sweep since the 2026-05 mini-Shai-Hulud burst. The batch is dominated by the 30-package sme-rko-finance-front-* dep-confusion cluster targeting Tinkoff / T-Bank's internal SME banking frontend namespace, joined by six qualitatively distinct outlier drops.

Cluster A - sme-rko-finance-front-* Tinkoff RKO dep-confusion / WEL1DROPPER-style cross-platform dropper (30 packages, all 35.8.1, 2026-08-08)

| Package | Version | GHSA | |---|---|---| | sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-models | 35.8.1 | GHSA-xfv4-g237-3qv8 | | sme-rko-finance-front-payments-currency-payment-domain | 35.8.1 | GHSA-pwjh-hjvr-rv33 | | sme-rko-finance-front-operations-overnight | 35.8.1 | GHSA-c9vg-pfhf-qxw9 | | sme-rko-finance-front-operations-providers | 35.8.1 | GHSA-cg6q-c6gh-62q2 | | sme-rko-finance-front-operations-shared | 35.8.1 | GHSA-pp5j-rx3f-4m7x | | sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models | 35.8.1 | GHSA-6hmr-8896-mrmx | | sme-rko-finance-front-operations-penalty | 35.8.1 | GHSA-h56m-2x6r-3fx2 | | sme-rko-finance-front-operations-tax | 35.8.1 | GHSA-p2hc-6684-r35c | | sme-rko-finance-front-payments-allowed-tariffs-filter | 35.8.1 | GHSA-mp53-hghj-9r7p | | sme-rko-finance-front-operations-widget-models | 35.8.1 | GHSA-gpvf-x5gg-r5cv | | sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl | 35.8.1 | GHSA-85v5-vfj6-7hw8 | | sme-rko-finance-front-payments-feed-adapter | 35.8.1 | GHSA-xprg-ffr4-2rw4 | | sme-rko-finance-front-operations-widget-domain | 35.8.1 | GHSA-q26r-96fx-86h6 | | sme-rko-finance-front-payments-domain | 35.8.1 | GHSA-pmc8-g84p-3x77 | | sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl | 35.8.1 | GHSA-8q7h-xvgq-ff27 | | sme-rko-finance-front-operations-widget-impl | 35.8.1 | GHSA-2phg-c6vf-892f | | sme-rko-finance-front-payments-feed-display-list | 35.8.1 | GHSA-6cqr-56m6-wch6 | | sme-rko-finance-front-operations-special-payments | 35.8.1 | GHSA-28cp-6vcg-8fhv | | sme-rko-finance-front-payment-registers-operations-domain | 35.8.1 | GHSA-vrgq-5852-3299 | | sme-rko-finance-front-operations-pegasus | 35.8.1 | GHSA-6fvh-4vgq-9765 | | sme-rko-finance-front-payments-feed-display-list-impl | 35.8.1 | GHSA-4wvm-26xh-fgjw | | sme-rko-finance-front-operations-domain | 35.8.1 | GHSA-4rj4-828w-hv35 | | sme-rko-finance-front-operations-holding-domain | 35.8.1 | GHSA-wm7f-4h9v-m4mm | | sme-rko-finance-front-operations-feed-models | 35.8.1 | GHSA-52qg-7wfr-wvgx | | sme-rko-finance-front-operations-other | 35.8.1 | GHSA-xqr4-4gx9-7w24 | | sme-rko-finance-front-operations-fee | 35.8.1 | GHSA-ffh6-w4x4-2j5q | | sme-rko-finance-front-operations-notifications-impl | 35.8.1 | GHSA-45vf-qpf8-q2pq | | sme-rko-finance-front-operations-notifications-models | 35.8.1 | GHSA-35pp-f297-w386 | | sme-rko-finance-front-operations-income | 35.8.1 | GHSA-6m9x-xq34-wgvq | | sme-rko-finance-front-operations-feed-impl | 35.8.1 | GHSA-j2hm-7vph-3whg |

Target profile: every name mimics a sme-rko-finance-front-* internal-scope pattern - "SME" = small/medium-enterprise, "RKO" = расчётно-кассовое обслуживание (settlement and cash services), the T-Bank / Tinkoff Business SME banking product line. This is a coordinated dep-confusion campaign against Tinkoff / T-Bank's internal SME banking frontend developer team, consistent with the pattern established in the 2026-05-29 Microsoft-disclosed @sber-ecom-core / Sberbank dep-confusion campaign - Russian financial-institution internal namespaces are under sustained enumeration by the same or a related operator.

Version-jump: every package pins to 35.8.1, well above any plausible v1.x-v3.x internal version. Classic dep-confusion tactic to ensure the malicious public package outranks the real private version in resolvers that fall back to the public registry.

Behaviour chain per GHSA-xfv4-g237-3qv8 and siblings: index.js loads _bridge.js which reconstructs a set of Cloudflare Workers URLs using obfuscated string methods, downloads a platform-specific binary payload (Linux/macOS/Windows detected by process.platform and process.arch), writes the payload under /var/tmp/<disguised-dotnet_diag-name> (Unix) or the Windows TEMP directory using dotnet_diag-impersonating filenames and hidden dotfiles, then executes the payload via child_process.spawn as a detached process. A parallel dropper in lib/telemetry.js uses concatenated string literals to evade detection and base64-decodes executable chunks before spawning them under false pretenses. DNS TXT-record fallback channels are used for configuration delivery if the primary Cloudflare Workers hosts are blocked, and filesystem stamps provide run-once deduplication so the payload only drops once per host.

Detection window: all 30 packages were unpublished from npmjs within ~8 minutes of publication - one of the fastest npm takedown response times observed for a cluster of this size, suggesting either OpenSSF Package Analysis auto-flagged the batch immediately or a tipoff from the target org triggered a coordinated takedown. Registry timing captured created: 2026-08-07T22:53Zunpublished: 2026-08-07T23:01Z for a representative package. The GHSA advisories were published the following calendar day (2026-08-08) after the OpenSSF sample-fetch + Amazon Inspector analysis pipeline completed.

Relationship to WEL1DROPPER: the technical profile - getPlugin-style URL construction, Cloudflare Workers dropper, cross-platform payload selection - matches the WEL1DROPPER campaign disclosed by Xygeni ("Malicious Code Digest 82") and covered in The Hacker News "Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer". The 800-package WEL1DROPPER wave targets a broader require()-based README-instruction distribution vector; the sme-rko-finance-front-* cluster uses the same dropper technology but ships as a straight postinstall dep-confusion drop against a specific target org.

Cluster B - @coralxyz/anchor Solana Anchor typosquat with Windows PowerShell zip drop (1 package, 2026-08-08)

| Package | Versions | Notes | |---|---|---| | @coralxyz/anchor | <= 0.30.2 | Typosquats @coral-xyz/anchor (hyphen removed), Windows postinstall zip-drop-then-execute |

Drops the hyphen from Solana's real @coral-xyz/anchor on-chain smart-contract dev framework. Postinstall runs obfuscated code; on Windows only, downloads a zip from an anonymous file host, extracts via PowerShell, and detach-executes any .exe found. Ships no genuine Anchor functionality - existing solely as a delivery vector. OpenSSF MAL-2026-13629; discovery credited to amazon-inspector.

Cluster C - titan-exchange-shared-permissions@99.9.9 dep-confusion recon (1 package, 2026-08-08)

| Package | Version | Notes | |---|---|---| | titan-exchange-shared-permissions | 99.9.9 | Version-jump dep-confusion, postinstall webhook recon |

Version 99.9.9 is the giveaway - designed to outrank any plausible-real internal version of a titan-exchange internal package. Postinstall collects username + hostname + cwd + IPv4 address and HTTPS-POSTs to a hardcoded webhook. Naming targets a titan-exchange internal scope, consistent with the crypto-exchange target profile. Advisory ships only recon; a stage-2 payload is likely to follow if the operator confirms the recon output identifies a live target org. OpenSSF MAL-2026-13664.

Cluster D - @rbx-ts/services Roblox TS typosquat with catbox.moe zip drop (1 package, 2026-08-08)

| Package | Versions | Notes | |---|---|---| | @rbx-ts/services | >= 1.6.0 | Marketed as Roblox TypeScript definitions, Windows-only catbox.moe zip drop |

Windows-only (process.platform === "win32" gate) postinstall. Uses hex-escaped identifiers and base64-encoded strings to hide https, fs, child_process, powershell, and .exe references. Decodes and fetches files.catbox.moe/9bppy2.zip, extracts via PowerShell, detach-executes the first .exe, then deletes evidence. Marketed as Roblox TypeScript type definitions (a plausibly-real name in the Roblox-TS ecosystem) with no legitimate reason for a bundled executable. OpenSSF MAL-2026-13630.

Cluster E - map-streak-kit Linux implant with systemd persistence + SSH-key theft (1 package, 2026-08-08)

| Package | Versions | Notes | |---|---|---| | map-streak-kit | 1.0.0 | Linux binary implant, C2 217.60.77.63, systemd persistence, SSH-key/env exfil |

Drops a disguised Linux binary claiming to be a "native math accelerator". Actual behaviour: beacons to C2 217.60.77.63, executes shell commands from C2, installs a systemd unit for boot persistence, and harvests SSH keys + stored credentials + environment variables for exfiltration. Most severe non-cluster-A drop of the batch - a working Linux RAT with persistence and credential theft, one npm-install away. OpenSSF MAL-2026-13632.

Cluster F - localization-fixer + modern-localization mutable-jsonbin.io payload loader pair (2 packages, 2026-08-08)

| Package | Versions | Notes | |---|---|---| | localization-fixer | <= 1.0.1, <= 1.1.1 | JSONbin.io mutable payload, child_process.fork + new Function() execution | | modern-localization | 1.1.1, 1.2.1 | JSONbin.io mutable payload, same execution shape |

Both fetch JavaScript payloads from attacker-controlled JSONbin.io endpoints on require() and execute via child_process.fork (writing to temp file and forking) plus new Function() constructor with Node's require in scope. Both use innocuous function names (syncLanguageSystem, LANG_SOURCE) to disguise as legitimate localization utilities.

The critical detail: because JSONbin.io bins are mutable and controlled by the operator, the payload can rotate silently at any moment without republishing to npm. Whatever the payload was during your install may bear no relationship to what a security researcher sees today. Treat both packages as full-capability RATs regardless of what the JSONbin.io endpoint currently serves. OpenSSF MAL-2026-13631 and MAL-2026-13633.

Distinction from lifecycle-hook malware: these packages run on require(), not preinstall/postinstall. npm ci --ignore-scripts does NOT mitigate them - the payload fires the first time the module is imported. Same execution vector as the Xygeni-flagged WEL1DROPPER wave.

Registry state

All 36 packages yanked / security-replaced from npm during the 2026-08-08 takedown. Registry timing suggests the takedown was extremely fast (~8 minutes for the sme-rko-finance cluster). Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions.

Related tracked activity

  • WEL1DROPPER umbrella campaign: Xygeni ("Malicious Code Digest 82") and The Hacker News (2026-08 "Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer") describe an 800-package WEL1DROPPER RAT + infostealer wave using cross-platform Cloudflare Workers droppers and the getPlugin require()-triggered execution model. The 30-package sme-rko-finance-front-* cluster catalogued here uses the same dropper technology but ships as a target-specific dep-confusion drop rather than as opportunistic README-instructed require()-load bait. The localization-fixer + modern-localization pair matches the require()-triggered WEL1DROPPER model more directly.
  • Russian financial-institution dep-confusion sequence: 2026-05-29 Microsoft Security Blog disclosed the @sber-ecom-core Sberbank-targeted dep-confusion campaign (33 packages). Today's sme-rko-finance-front-* cluster is the same TTP applied to Tinkoff / T-Bank's SME (RKO) banking frontend namespace. Coordinated targeting of Russian financial developer teams via dep-confusion is now a recurring pattern - watch for further @sber-*, @tinkoff-*, @vtb-*, @raiff-*, @alfa-* internal-scope clusters in the coming daily batches.
  • Solana ecosystem typosquat pressure: @coralxyz/anchor (this batch) joins prior @sui-migration-audit-*, @move-* (npm 2026-08-06), alphalend-* (PyPI 2026-08-07) as the third consecutive-day cross-language attack on the Solana/Sui developer ecosystem.
  • Discovery credits: OpenSSF malicious-packages, OpenSSF Package Analysis, npm Security, amazon-inspector. No named threat actor - MAL-2026-*(13486..13664) identifiers only.

Affected packages (47)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • *Cluster A - `sme-rko-finance-front- Tinkoff RKO dep-confusion / WEL1DROPPER cross-platform dropper** (30 packages, all 35.8.1, 2026-08-08): every package name mimics the T-Bank / Tinkoff internal SME banking (RKO) frontend package namespace (e.g. sme-rko-finance-front-payments-domain, sme-rko-finance-front-operations-widget-impl, sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models). On install, _bridge.js selects a platform-specific asset path, **downloads bytes from a rotating set of Cloudflare Workers endpoints**, writes the payload under /var/tmp (Unix) or %TEMP% (Windows) using **disguised names impersonating dotnet_diag and hidden dotfiles**, and executes it with detached process spawn. A parallel dropper in lib/telemetry.js` handles redundancy and uses DNS TXT-record fallback channels for C2 configuration if the Workers endpoints are blocked. Runtime string reconstruction, run-once deduplication via filesystem stamps, and base64 chunk decoding evade static analysis. Any T-Bank / Tinkoff SME dev whose CI resolved any of the 30 packages must treat the CI runner as fully compromised at the native-code level. All 30 versions were unpublished from npmjs within ~8 minutes of publication - private mirrors that cached tarballs in that window are the only remaining exposure route
  • Cluster B - @coralxyz/anchor Solana Anchor framework typosquat (1 package, <= 0.30.2, 2026-08-08): removes the hyphen from the real @coral-xyz/anchor framework (Solana on-chain smart-contract dev framework). Postinstall runs obfuscated code that on Windows downloads a zip from an anonymous file host, extracts it via PowerShell, and executes any .exe inside as a detached process. The package ships no genuine Anchor functionality - it exists only as a Windows-only Solana-developer-targeted RAT delivery mechanism
  • Cluster C - titan-exchange-shared-permissions@99.9.9 dep-confusion reconnaissance (1 package, 99.9.9, 2026-08-08): version-jump to 99.9.9 outranks any plausible real internal package version. Postinstall harvests username + hostname + cwd + IPv4 address and HTTPS-POSTs to a hardcoded webhook. Naming targets a titan-exchange internal scope - likely a crypto-exchange internal package namespace under active reconnaissance. Advisory carries only recon behaviour; a stage-2 payload matching the recon results is likely to follow if the operator confirms a live target org
  • Cluster D - @rbx-ts/services Roblox TypeScript definitions typosquat (1 package, >= 1.6.0, 2026-08-08): masquerades as Roblox TypeScript type definitions (a plausible-real name in the Roblox-TS ecosystem). Windows-only postinstall (process.platform === "win32" gate) decodes a hex-escaped + base64-encoded fetch URL, downloads a zip from files.catbox.moe/9bppy2.zip, extracts via PowerShell, and detach-executes the first .exe before deleting evidence. Anonymous file host means the payload can rotate silently
  • Cluster E - map-streak-kit Linux implant with systemd persistence (1 package, 1.0.0, 2026-08-08): on import, drops a Linux binary disguised as a "native math accelerator", beacons to hardcoded C2 217.60.77.63, executes shell commands from C2, installs a systemd unit for boot persistence, and harvests SSH keys + stored credentials + environment variables for exfiltration. Any Linux CI runner or dev workstation that imported this package must be treated as fully compromised - re-image the host and rotate every SSH key + credential + env-var secret
  • Cluster F - localization-fixer + modern-localization mutable-jsonbin.io payload-loader pair (2 packages, 2026-08-08): both fetch JavaScript payloads from attacker-controlled JSONbin.io endpoints on package initialisation and execute via child_process.fork + new Function() with Node's require capability. Because the JSONbin bins are mutable, the payload can change at any time between installs - the operator can silently update the RAT/stealer without republishing to npm. Marketed as innocuous "localization" helpers with function names like syncLanguageSystem and LANG_SOURCE

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for the full 2026-08-08 package list below - especially the 30 sme-rko-finance-front-* names (any T-Bank / Tinkoff CI hit is a native-code compromise), @coralxyz/anchor, titan-exchange-shared-permissions, @rbx-ts/services, map-streak-kit, localization-fixer, modern-localization
  2. 2*For any `sme-rko-finance-front- match (critical)**: treat the affected host as fully compromised at the native-code level. Native binary was written to /var/tmp/<disguised-dotnet_diag-name> on Unix or %TEMP%\<disguised-dotnet_diag-name> on Windows, may have installed persistence, and connected to Cloudflare Workers C2 with DNS TXT fallback. Kill any process matching the dotnet_diag or hidden-dotfile pattern in those directories, block outbound to .workers.dev` at the network egress, re-image the affected host, and rotate every credential (npm tokens, cloud, VCS, CI) that lived on it. If you are inside T-Bank / Tinkoff SME infrastructure, escalate to internal security immediately: this is a live active dep-confusion attempt against your internal RKO namespace
  3. 3For @coralxyz/anchor matches: uninstall, block the package name in .npmrc. On Windows, hunt for the PowerShell-extracted staged .exe under %TEMP% from within the exposure window and any executable spawned as a detached process during install. Correct the typo to the real @coral-xyz/anchor (with hyphen)
  4. 4For titan-exchange-shared-permissions@99.9.9 matches: your username + hostname + cwd + IP have already been sent to the operator. Treat as dep-confusion scope disclosure; configure .npmrc scope-to-registry mapping so titan-exchange-* internal names resolve only from your private mirror. Watch for a stage-2 malicious drop under the same name in the next daily GHSA batches
  5. 5For @rbx-ts/services matches: any host with a stored Roblox studio session, Roblox account cookie, or crypto wallet accessible to the Windows user must be considered compromised. Rotate Roblox credentials, revoke Roblox API keys, and hunt for the catbox.moe-fetched .exe under %TEMP%
  6. 6For map-streak-kit matches: most severe non-cluster-A remediation. Re-image the affected Linux host from bare metal, rotate every SSH key on the host (including any private key with the same fingerprint reused elsewhere), rotate every credential stored in env or config files, and remove any systemd unit created in the exposure window. C2 217.60.77.63 should be blocked at the network egress and its network flows tracked
  7. 7For localization-fixer / modern-localization matches: the historical payload does not fully characterise the risk - the JSONbin.io payload is mutable and could have been anything at the moment your install ran. Treat both packages as fully-compromised RATs regardless of what the JSONbin.io endpoint returns today. Block outbound to api.jsonbin.io from any host that installed either package during the exposure window and audit process creation / network flow logs for whatever the payload actually did during install
  8. 8For all npm installs in CI, run with --ignore-scripts as defense-in-depth to prevent preinstall/postinstall payloads from executing (mitigates Clusters A-E; does NOT mitigate F, which runs on require rather than lifecycle hook)
  9. 9Verify none of the 2026-08-08 packages still resolves via your private mirror - internal caches routinely keep serving yanked tarballs after the public takedown

References

npm-2026-08-08-ghsa-malware-sweep