VDB
EN

MAL-2026-12278

Malicious code in tinkoff-statist-browser-typed-client-test.softwarecenter.metrics (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d9027d7179ebd421765074cbde727f3a3e358eb677a9a9125fb22ff6638fd799) The package's index.js requires./setup on module load. setup.js selects a platform-specific output path (/var/tmp/.cache_<hex> on unix, %TEMP%/dotnet_diag_<hex>.exe on Windows), fetches bytes over HTTPS from Cloudflare Workers hosts whose names are assembled at runtime from split-string fragments joined together (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), with DNS TXT-record fallback destinations (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site). The fetched payload is written to disk, chmod 0755 on unix, and spawned detached via /bin/sh -c or cmd.exe /c start. There is no hash or signature verification, no publisher relationship to the destination hosts, and no relationship between the fetched binary and any advertised functionality. Cover-story naming (analytics_state identifier, dotnet_diag_*.exe filename, DISABLE_TELEMETRY env-var opt-out) is used to mimic legitimate telemetry, and the package name typosquats a Tinkoff internal scope. The hostname obfuscation via.join("") on split fragments is a deliberate evasion pattern.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tinkoff-statist-browser-typed-client-test.softwarecenter.metrics

No fixed version published yet for tinkoff-statist-browser-typed-client-test.softwarecenter.metrics (npm). Pin to a known-safe version or switch to an alternative.

참고