VDB
KO

MAL-2026-12261

Malicious code in tinkoff-statist-browser-typed-client-investaccounting.events.templatepage.mainpage (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (01843210cccc7d6327d870fbe2f8d53a493aa8d1db525de7473f30f97ea9dcdb) On require of the package, index.js loads _bridge.js which assembles Cloudflare Workers hostnames by joining split string fragments (e.g. ['oob-worker.c','f103','-070.w','orkers.d','ev'].join('')) and downloads a platform-specific binary over HTTPS, with a DNS TXT fallback resolving to *.dl.well1.site (e.g. ['tin.dl.well1.','si','te'].join('')). The binary is written to /var/tmp/.cache_<rand> on Linux or %TEMP%/dotnet_diag_<rand>.exe on Windows, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start at _bridge.js:120-126. Cover-story comments and env-var opt-outs (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, DO_NOT_TRACK) frame the drop-and-exec as telemetry; a lib/telemetry.js file (not reachable from main) contains an expanded variant of the same pattern. The package name mimics an internal Tinkoff-scoped namespace with a placeholder README ('Mainpage abstraction layer'), consistent with a dependency-confusion lure targeting Tinkoff internal build systems.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tinkoff-statist-browser-typed-client-investaccounting.events.templatepage.mainpage

No fixed version published yet for tinkoff-statist-browser-typed-client-investaccounting.events.templatepage.mainpage (npm). Pin to a known-safe version or switch to an alternative.

References