VDB
EN

MAL-2026-12240

Malicious code in tinkoff-fb-app-frame-page-height-dippy (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5db9a5313417dcbe6f8514736de7dd82892ad5cdccc261e0064d8f76f8d9613e) On require, index.js loads _platform.js, which reconstructs C2 hostnames via runtime string concatenation (joining fragments such as 'oob-worker.cf101-adf.workers.de'+'v' and 'tin.dl.well1'+'.si'+'te'), selects a per-OS/architecture binary, and downloads bytes over HTTPS from one of four anonymous Cloudflare Workers subdomains (oob-worker.cf101-adf.workers.dev, cf102-, cf103-, cf104-) with a DNS TXT-record fallback via well1.site. The retrieved payload is written to /tmp as a hidden dot-file (e.g. /tmp/.cache_<rand>,.analytics_state lock file) on POSIX or to %TEMP% as dotnet_diag_<rand>.exe on Windows, chmodded 0755, and spawned detached via /bin/sh -c '<path> &' or cmd /c start. A shipped lib/telemetry.js further concatenates 'child_'+'process' and 'chmod'+'Sync' to evade static analysis. The package name and description bear no relation to this behavior; the entire on-require code path is a binary dropper executing attacker-controlled native code on the installer's host.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tinkoff-fb-app-frame-page-height-dippy

No fixed version published yet for tinkoff-fb-app-frame-page-height-dippy (npm). Pin to a known-safe version or switch to an alternative.

참고