Logo
npm

tinkoff-statist-browser-typed-client-sme.platform.mobile.dynamicteasers.common@20.8.7

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 11:33 AM UTC

Malicious

OSV ID

MAL-2026-12270

Ecosystem

npm

Summary

On require/import, index.js loads _bridge.js which selects a platform-specific endpoint and downloads an opaque executable over HTTPS from hardcoded hosts assembled via string-join obfuscation (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT chunked base64 fallback via *.dl.well1.site. The downloaded bytes are written to disguised paths (/var/tmp/.cache_<hex> on Unix, %TEMP%\dotnet_diag_<hex>.exe on Windows), chmod'd 0o755, and spawned detached via /bin/sh -c or cmd /c start /b. Hostnames are reconstructed from character-fragment arrays via.join(), staging filenames masquerade as system diagnostics/cache artifacts, and DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env checks are used as cover. The package name presents as a scoped Tinkoff internal client but the shipped code performs full remote code execution on the installer's host at load time.

Source: amazon-inspector (cd094a1c3c67af1fc7372e62ed565847fcf26962f3b90e53a5df200390c07a99)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.