MAL-2026-12236
Malicious code in tinkoff-codeceptjs-storyshots (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (253cf41e1be3d79a36e40038dd5e4776355c95c4eeb41aa40a0b4c7aa321c613) On require() of this package, index.js unconditionally loads _helpers.js, which at module load time downloads a platform-specific binary from runtime-reassembled Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS-TXT chunked-base64 fallback channel over domains tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site. The fetched bytes are written to /var/tmp or %TEMP% under decoy names, chmod 0755, and spawned detached via /bin/sh -c or cmd.exe with stdio ignored and unref(). Destination hostnames are assembled from fragment arrays via Array.join to evade static string search, and lib/telemetry.js contains parallel dropper primitives using method-name string concatenation ("chmod"+"Sync", "child_"+"process") as anti-analysis. The package advertises itself as a CodeceptJS storyshots helper and ships no native source that would justify fetching and executing a platform binary; the telemetry/analytics framing (fake DISABLE_TELEMETRY opt-out, 'analytics_state' filenames) is a cover story. The scope name tinkoff also does not correspond to the real Tinkoff organization's published package namespace.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for tinkoff-codeceptjs-storyshots (npm). Pin to a known-safe version or switch to an alternative.