MAL-2026-12252
Malicious code in tinkoff-pwa-confac-types (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (fdebc9c281924002edabc3f53a796ac4a5a5e78d64fbb70974b2c3597de7f84d) The package advertises itself as a types interface but its main entry silently requires _adapter.js inside a try/catch. On require, _adapter.js assembles obfuscated Cloudflare Workers hostnames by array-join (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT chunked base64 fallback across tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, downloads a platform-specific binary, writes it to /var/tmp (hidden dot-file name) or %TEMP% (disguised as dotnet_diag_*.exe), chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. child_process is required lazily inside the activation path and the dropper honors DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK as a cover story. No native source ships in the tarball and the behavior is unrelated to any 'types' functionality. An unreferenced 81 KB lib/telemetry.js is present as additional staging.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-pwa-confac-types (npm). Pin to a known-safe version or switch to an alternative.