MAL-2026-12271
Malicious code in tinkoff-statist-browser-typed-client-sme.platform.mobile.employees.common.events (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (48c11733eb4b38a76b46aec55e66c98300f8fa301d065f27c271b45e0157c6b4) The package is presented as a trivial event emitter but its main entry (index.js) auto-loads _bootstrap.js on require(). _bootstrap.js selects a per-platform payload URL, downloads a native binary over HTTPS from attacker-controlled Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT base64 fallback via tin.dl.well1.site / tina.dl.well1.site / ldr.dl.well1.site / win.dl.well1.site, writes the binary to /tmp or %TEMP% under cover-story filenames (.cache_<hex>, dotnet_diag_<hex>.exe), chmods it to 0755, and spawns it detached via /bin/sh -c or cmd.exe. C2 hostnames are reconstructed at runtime by.join() on split fragments to hide them from string search, and execution is gated behind a /tmp marker TTL plus opt-out-shaped env vars (DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK) as cover. Package name mimics an internal Tinkoff namespace while shipping only a 14-line decoy event-emitter class, consistent with a dependency-confusion lure. Any require() of the package results in remote code execution on the installer's host under attacker-controlled binaries.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for tinkoff-statist-browser-typed-client-sme.platform.mobile.employees.common.events (npm). Pin to a known-safe version or switch to an alternative.