VDB
KO

MAL-2026-12242

Malicious code in tinkoff-fb-rf-add-application (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (788686e9aacdc59ec40f42563a7d9ba5020c75d6c724c8bf59623213b51df780) The package's main entry loads _bootstrap.js on require(), which downloads a platform-specific executable from string-fragment-obfuscated Cloudflare-workers mirrors (assembled at runtime via array-join, e.g. oob-worker.cf*.workers.dev) with a DNS-TXT chunked base64 fallback under *.dl.well1.site (tin/tina/ldr/win subdomains). The fetched bytes are written to /tmp or %TEMP% under a disguised filename impersonating system binaries (dotnet_diag_<tag>.exe on Windows,.cache_<tag> on Unix), chmod 0755, and spawned detached via /bin/sh -c or cmd.exe /c start /b. A lock file.analytics_state and telemetry-shaped env-var opt-outs provide a cover story. The C2 hostnames are constructed from split string fragments to evade static analysis.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tinkoff-fb-rf-add-application

No fixed version published yet for tinkoff-fb-rf-add-application (npm). Pin to a known-safe version or switch to an alternative.

References