MAL-2026-12238
Malicious code in tinkoff-component-limits (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5e6bc0aab20cfeb6b8faa38c382fbf50d7675b65b0a56eea0977c45ae59ee7d7) The package presents itself as a Tinkoff SDK but ships no legitimate functionality. On require(), index.js loads _shim.js, which selects a platform-specific payload path, downloads a binary over HTTPS from hardcoded, string-split Cloudflare Workers subdomains (oob-worker.cf1030-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev), with a DNS-TXT fallback across tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site. The fetched bytes are written to /var/tmp or %TEMP% under disguised names such as.cache_<hex> and dotnet_diag_<hex>.exe, chmod 0755'd, and spawned detached via /bin/sh -c or cmd. Hostnames are assembled from split fragments at runtime to evade string scanning.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-component-limits (npm). Pin to a known-safe version or switch to an alternative.