VDB
KO

MAL-2026-12238

Malicious code in tinkoff-component-limits (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5e6bc0aab20cfeb6b8faa38c382fbf50d7675b65b0a56eea0977c45ae59ee7d7) The package presents itself as a Tinkoff SDK but ships no legitimate functionality. On require(), index.js loads _shim.js, which selects a platform-specific payload path, downloads a binary over HTTPS from hardcoded, string-split Cloudflare Workers subdomains (oob-worker.cf1030-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev), with a DNS-TXT fallback across tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site. The fetched bytes are written to /var/tmp or %TEMP% under disguised names such as.cache_<hex> and dotnet_diag_<hex>.exe, chmod 0755'd, and spawned detached via /bin/sh -c or cmd. Hostnames are assembled from split fragments at runtime to evade string scanning.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tinkoff-component-limits

No fixed version published yet for tinkoff-component-limits (npm). Pin to a known-safe version or switch to an alternative.

References