MAL-2026-12248
Malicious code in tinkoff-pfp-block-mobile-advert-footer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (12bd549b3c3a286caedd91cb1bbc6052850f23c01f5eaa33e7c336db1928258c) On require() of index.js, the package silently loads _bootstrap.js, which reconstructs attacker-controlled hostnames from split-string fragments (oob-worker.cf102-baf.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf99-9b3.workers.dev, with a DNS-TXT base64 fallback via subdomains of dl.well1.site) and downloads an unsigned platform-specific binary over HTTPS. The binary is written to /var/tmp/.cache_<rand> on Unix or %TEMP%/dotnet_diag_<rand>.exe on Windows (a masquerade as a.NET diagnostic tool), chmod 0755, and detached-spawned via /bin/sh -c or cmd /c start. Re-execution is throttled by a state file (/tmp/.analytics_state or %TEMP%/analytics_state) checked against a MAX_AGE window. The package name impersonates Tinkoff internal tooling; the only functional code beyond a stub API surface is the dropper. Host reconstruction via array joins and the DNS-TXT payload transport are anti-analysis evasion.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-pfp-block-mobile-advert-footer (npm). Pin to a known-safe version or switch to an alternative.