VDB
EN

MAL-2026-12270

Malicious code in tinkoff-statist-browser-typed-client-sme.platform.mobile.dynamicteasers.common (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cd094a1c3c67af1fc7372e62ed565847fcf26962f3b90e53a5df200390c07a99) On require/import, index.js loads _bridge.js which selects a platform-specific endpoint and downloads an opaque executable over HTTPS from hardcoded hosts assembled via string-join obfuscation (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT chunked base64 fallback via *.dl.well1.site. The downloaded bytes are written to disguised paths (/var/tmp/.cache_<hex> on Unix, %TEMP%\dotnet_diag_<hex>.exe on Windows), chmod'd 0o755, and spawned detached via /bin/sh -c or cmd /c start /b. Hostnames are reconstructed from character-fragment arrays via.join(), staging filenames masquerade as system diagnostics/cache artifacts, and DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env checks are used as cover. The package name presents as a scoped Tinkoff internal client but the shipped code performs full remote code execution on the installer's host at load time.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tinkoff-statist-browser-typed-client-sme.platform.mobile.dynamicteasers.common

No fixed version published yet for tinkoff-statist-browser-typed-client-sme.platform.mobile.dynamicteasers.common (npm). Pin to a known-safe version or switch to an alternative.

참고