VDB
KO

MAL-2026-12244

Malicious code in tinkoff-mutual-mgm-form (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (84bc64dc52d6f64a0673f548b3201cc6eed96ea71665ccd1fc1a41b29ac12cca) On require('tinkoff-mutual-mgm-form'), index.js loads _compat.js, which selects a platform-specific asset path and fetches a native binary over HTTPS from Cloudflare Workers subdomains assembled via array.join('') string concatenation (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with a DNS TXT chunked fallback to look-alike hosts under dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched bytes are written to a masquerading path in /var/tmp or %TEMP% (e.g., dotnet_diag_<rnd>.exe or.cache_<rnd>), chmodded to 0755, and spawned detached via /bin/sh -c '<path> &' or cmd.exe start /b. The require('child_process') module name is also split-string obfuscated, and cover-story comments frame the behavior as 'telemetry' and 'session tracking'. A second copy of the same fetch-write-chmod-spawn dropper is bundled in lib/telemetry.js as an 'Analytics SDK', staged as an alternate payload. Destinations, obfuscation, masquerading filenames, and detached execution are inconsistent with the package's declared purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tinkoff-mutual-mgm-form

No fixed version published yet for tinkoff-mutual-mgm-form (npm). Pin to a known-safe version or switch to an alternative.

References