VDB
KO

MAL-2026-12259

Malicious code in tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2d381f80d9b2d3b310ab426d3c51996861b4c320f2926e53ea078da80e832a07) On require() of this package, index.js loads _vendor.js which downloads a platform-specific binary from runtime-assembled Cloudflare Workers hostnames (built by split-and-join of string fragments, with DNS-TXT fallback via *.dl.well1.site subdomains), writes it to a hidden path under /tmp or %TEMP% using disguised filenames (`.cache_<uid>` on POSIX, `dotnet_diag_<uid>.exe` on Windows), sets mode 755 via fs.chmodSync, and spawns it detached with cp.spawn('/bin/sh', ['-c', path+' &'], {detached:true}).unref() or cmd.exe start /b. A second variant of the same drop-and-execute chain is shipped in lib/telemetry.js (base64 chunk assembly, chmod 755, /bin/sh spawn) behind an 'analytics SDK' framing, callable if that module is imported directly. Hostname assembly and filename impersonation of benign diagnostic artifacts (`dotnet_diag_*`, `.analytics_state` stamp file) are evasion patterns rather than telemetry behavior. Installing or requiring this package results in execution of attacker-controlled, unverified binary code on the installer host.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks

No fixed version published yet for tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks (npm). Pin to a known-safe version or switch to an alternative.

References