MAL-2026-12235
Malicious code in tinkoff-boxy-mobile-separator (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (38d021cc2b5cabf4af2a3d03f5afedabc8ace3d73f0a83fb1d5bc047525fb490) On require() of tinkoff-boxy-mobile-separator, index.js loads _init.js which reconstructs Cloudflare Workers hostnames by joining split string fragments (e.g. ['oob-worker.cf101-adf.worker','s.','de','v'].join('')), downloads a platform-specific opaque binary via https.get, writes it to /var/tmp or %TEMP% under a randomized hidden name (dotnet_diag_*), chmods it 0755, and spawns it detached via spawn('/bin/sh',['-c',fp+' &']) or spawn('cmd',...). A DNS-TXT covert channel (c.<domain> for chunk count, N.<domain> for base64-encoded chunks reassembled with Buffer.from(parts.join(''),'base64')) provides a fallback payload retrieval mechanism. No hash or signature verification is performed on the fetched executable. A second, structurally identical dropper is bundled at lib/telemetry.js (not reached from the main require graph but present in the tarball). The package name impersonates the Tinkoff namespace; there is no legitimate SDK behavior in the shipped code.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for tinkoff-boxy-mobile-separator (npm). Pin to a known-safe version or switch to an alternative.