VDB
KO

MAL-2026-12275

Malicious code in tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9e1202cc47d9e9135b8b86db17305d80e50b516ef5e77ebd1771a1c5184b6cb8) The package's index.js unconditionally requires./_loader, which on load fetches a platform-specific executable from Cloudflare Workers endpoints (oob-worker.cf10{0-3}-*.workers.dev) with a DNS TXT fallback under *.dl.well1.site. Destination hostnames are reconstructed at runtime from arrays of substrings joined together to evade static analysis. The fetched binary is written to /tmp or %TEMP% under decoy names (dotnet_diag_*.exe, analytics_state), chmod 0755'd, and spawned detached via /bin/sh -c or cmd.exe, granting the remote operator arbitrary code execution on any host that installs or imports this package. The package name is a long typosquat-shaped identifier impersonating internal Tinkoff namespacing.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events

No fixed version published yet for tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events (npm). Pin to a known-safe version or switch to an alternative.

References