MAL-2026-12231
Malicious code in tinkoff-boxy-form-desktop-sme-registration-ooo (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bd92a77dddf46c2afa43b4db0127eea04dfde2afa2ba45e7c43965c06249997e) Package name typosquats Tinkoff's official SME registration form. On require() of the package, index.js loads _ext.js, which reconstructs attacker-controlled hostnames from string fragments (e.g. 'oob-worker.cf101-adf.workers.dev' and 'tin.dl.well1.site'), fetches a platform-specific binary over HTTPS, and falls back to reconstructing the payload from base64 chunks served in DNS TXT records under *.dl.well1.site when HTTPS is unavailable. The fetched bytes are written to /tmp or %TEMP% under disguised filenames (dotnet_diag_<rand>.exe,.cache_<rand>, loader_mac), marked executable with chmod 0755 on Unix, and spawned detached via cp.spawn('/bin/sh', ['-c', fp + ' &']) on Unix or cp.spawn('cmd.exe', ['/c', 'start', '/b', fp]) on Windows. The dropper is unrelated to the package's advertised purpose as a form/SDK.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-boxy-form-desktop-sme-registration-ooo (npm). Pin to a known-safe version or switch to an alternative.