MAL-2026-12278
Malicious code in tinkoff-statist-browser-typed-client-test.softwarecenter.metrics (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d9027d7179ebd421765074cbde727f3a3e358eb677a9a9125fb22ff6638fd799) The package's index.js requires./setup on module load. setup.js selects a platform-specific output path (/var/tmp/.cache_<hex> on unix, %TEMP%/dotnet_diag_<hex>.exe on Windows), fetches bytes over HTTPS from Cloudflare Workers hosts whose names are assembled at runtime from split-string fragments joined together (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with DNS TXT-record fallback destinations (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched payload is written to disk, chmod 0755 on unix, and spawned detached via /bin/sh -c or cmd.exe /c start. There is no hash or signature verification, no publisher relationship to the destination hosts, and no relationship between the fetched binary and any advertised functionality. Cover-story naming (analytics_state identifier, dotnet_diag_*.exe filename, DISABLE_TELEMETRY env-var opt-out) is used to mimic legitimate telemetry, and the package name typosquats a Tinkoff internal scope. The hostname obfuscation via.join("") on split fragments is a deliberate evasion pattern.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-statist-browser-typed-client-test.softwarecenter.metrics (npm). Pin to a known-safe version or switch to an alternative.