-= Per source details. Do not edit below this line.=-
Package publishes as skrill-sdk and exposes a PaysafeClient API (payments.create/get, customers.create/get) that mimics an official Skrill/Paysafe payments SDK but implements no real payment functionality — client methods return a stub {success:true}. When a client method is invoked with an API key configured, the package schedules a delayed (~17.8s) exfiltration that collects the machine hostname, username, current working directory, a filtered subset of process.env matching credential-shaped substrings (key/secret/token/pass/auth/api), the first 10 chars of the caller's API key, and package identifiers, then POSTs the JSON payload over HTTPS to a hardcoded remote host on port 8443. The C2 hostname, module names, HTTP headers, and env-var filter substrings are XOR-decoded from base64 blobs to hide them from static inspection, and a __check() guard suppresses exfiltration when CPU count is low or hostname/username matches a sandbox/analysis denylist. The brand-impersonating name plus fake API surface is designed to lure developers into instantiating the client with production Skrill/Paysafe credentials, which are then harvested along with any credential-shaped environment variables on the developer or CI host.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010377",
"import_time": "2026-07-14T04:31:59.715388105Z",
"modified_time": "2026-07-14T03:38:10Z",
"sha256": "61b89b04fbb6a34ea37a855c5ee938aa6c4f91cc2e79d9880d14436a09b2e8a5",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed",
"tlsh": "2e617770b199a93b76a08fd598724006de4d99013d45f3e3b7ac78cd5e536b2c1e683c"
}
],
"package_integrity": [
{
"filename": "skrill-sdk-1.0.0.tgz",
"hashes": {
"sha1": "8db42622966db0e759c7d226fc69afa81b0f5bd1",
"sha512_sri": "sha512-wX9ASGK6xz6x2PfM9uc4+lGDgsFj9CnoXLQE5Afkjwc1Q2ZqpNo2HiUy/9oYWFFKRMOSXYQAJcM+YqgDoi/5yQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/skrill-sdk/MAL-2026-10544.json"