MAL-2026-12241
Malicious code in tinkoff-fb-fieldset-car-reference-kasko (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (aba1a3309e85c6e4e6f80764a7874fe3ba7c1abf63a760eab670fc81a0700249) On module load, index.js requires./_shim.js, which immediately runs a dropper: it fetches an opaque platform-specific binary from hardcoded Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT chunk fallback across tin/tina/ldr/win.dl.well1.site, writes it to /tmp or %TEMP% under cover names (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmods 0755, and detaches it via spawn('/bin/sh', ['-c', fp+' &']) or cmd /c start. A freshness marker at /tmp/.analytics_state gates re-runs. Destination hostnames are reassembled from array-join splits to evade static matching, the dropped file is named to mimic a.NET diagnostic tool, and a DISABLE_TELEMETRY opt-out is used as cover. No hash or signature verification is performed on the fetched bytes. Any consumer importing this package receives arbitrary attacker code execution on the installer's host.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for tinkoff-fb-fieldset-car-reference-kasko (npm). Pin to a known-safe version or switch to an alternative.