MAL-2026-12268
Malicious code in tinkoff-statist-browser-typed-client-mb.product.tgeofencing (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (471fb9b5c8d45abc59ffda97063561b4882d28109c9959c717fbcd0d9f25c00d) On require() of this package, index.js loads _platform.js which assembles remote hostnames at runtime by concatenating fragmented string arrays to hide them from static scanners. The resolved hosts include oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, and tin/tina/ldr/win.dl.well1.site, with a DNS-TXT chunked base64 fallback channel. The module downloads an opaque binary via https.get, writes it to /tmp or %TEMP% under disguised names impersonating.NET diagnostics (dotnet_diag_<hex>.exe,.cache_<hex>), chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. A sibling file lib/telemetry.js ships the same dropper shape (child_process require string-split as require("child_"+"process"), chmodSync via fs["chmod"+"Sync"], cp.spawn("/bin/sh", ["-c", filePath+" &"])) as a staged secondary payload, though it is not reached from index.js in this version. The fetched-and-executed binaries, obfuscated destinations, disguised filenames, and DNS-TXT fallback do not match the package's declared Tgeofencing purpose. The package name also impersonates a Tinkoff internal-scope package, consistent with a dependency-confusion lure.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-statist-browser-typed-client-mb.product.tgeofencing (npm). Pin to a known-safe version or switch to an alternative.