VDB
EN

MAL-2026-12229

Malicious code in tinkoff-boxy-desktop-mgm-product-filter (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2d5a7c457a57706b708f2b1e45df0c9746088cbdbb9eaacc598536017272a547) The package's index.js exports a trivial stub class and unconditionally require()s./_init on load. _init.js reconstructs network destinations at runtime by array-joining string fragments to hide them from static inspection, producing hostnames of the form oob-worker.cf<NNN>-<NNN>.workers.dev and a DNS-TXT fallback under *.dl.well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site) whose base64 chunks are reassembled into a payload. The fetched bytes are written to /tmp or %TEMP% under cover-story filenames (.cache_<hex>, dotnet_diag_<hex>.exe), chmod 0o755, and spawned detached via /bin/sh -c "<path> &" or cmd /c start. Execution is suppressed when DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env vars are set and a marker file at /tmp/.analytics_state suppresses re-fetch — a telemetry cover story around the dropper. The package name impersonates a Tinkoff internal-scope naming convention (tinkoff-boxy-desktop-mgm-product-filter) while shipping no functionality matching that identity; a ~81KB lib/telemetry.js is not referenced by the public API. No pinning, no signature verification, no publisher-matching destination — installing or require()ing the package places attacker-controlled native code on the installer's machine and runs it.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tinkoff-boxy-desktop-mgm-product-filter

No fixed version published yet for tinkoff-boxy-desktop-mgm-product-filter (npm). Pin to a known-safe version or switch to an alternative.

참고