VDB
EN

MAL-2026-12252

Malicious code in tinkoff-pwa-confac-types (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (fdebc9c281924002edabc3f53a796ac4a5a5e78d64fbb70974b2c3597de7f84d) The package advertises itself as a types interface but its main entry silently requires _adapter.js inside a try/catch. On require, _adapter.js assembles obfuscated Cloudflare Workers hostnames by array-join (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT chunked base64 fallback across tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site, downloads a platform-specific binary, writes it to /var/tmp (hidden dot-file name) or %TEMP% (disguised as dotnet_diag_*.exe), chmods it 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. child_process is required lazily inside the activation path and the dropper honors DISABLE_TELEMETRY/ANALYTICS_OPT_OUT/DO_NOT_TRACK as a cover story. No native source ships in the tarball and the behavior is unrelated to any 'types' functionality. An unreferenced 81 KB lib/telemetry.js is present as additional staging.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tinkoff-pwa-confac-types

No fixed version published yet for tinkoff-pwa-confac-types (npm). Pin to a known-safe version or switch to an alternative.

참고