{"id":"MAL-2026-12076","summary":"Malicious code in tinkoff-cache-path (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9db3a162bd8fe3b6112b6d058e42245617122a41941d0b3a818254aba25ce59b)\nThe package advertises itself as an in-memory cache utility, but index.js unconditionally requires _compat.js on load, which acts as a dropper. _compat.js selects a platform-specific endpoint from an obfuscated list of hosts assembled at runtime via Array.join (oob-worker.cf*.workers.dev and *.dl.well1.site), downloads an opaque native binary over HTTPS, and falls back to a DNS-TXT covert channel that queries a count record at c.\u003cdomain\u003e and reassembles numbered base64 TXT chunks into an executable buffer. The payload is written under /var/tmp or %TEMP% with a disguised name (.cache_\u003crand\u003e on Unix, dotnet_diag_\u003crand\u003e.exe on Windows), chmod +x, and spawned detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"], {detached:true}).unref() or spawn(\"cmd\",...). A.analytics_state marker file and DO_NOT_TRACK-shaped environment opt-outs are used as cover. The declared purpose (caching) has no relationship to fetching and executing a native binary from attacker-controlled infrastructure.\n","modified":"2026-08-05T03:20:55.787475544Z","published":"2026-08-05T01:40:03Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T03:11:15.531452205Z","modified_time":"2026-08-05T01:40:03Z","sha256":"9db3a162bd8fe3b6112b6d058e42245617122a41941d0b3a818254aba25ce59b","source":"amazon-inspector","versions":["20.8.3"],"id":"IN-MAL-2026-011509"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tinkoff-cache-path/v/20.8.3"}],"affected":[{"package":{"name":"tinkoff-cache-path","ecosystem":"npm","purl":"pkg:npm/tinkoff-cache-path"},"versions":["20.8.3"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"tinkoff-cache-path-20.8.3.tgz","hashes":{"sha1":"64a9e95fc6b351e8cadc3720f5a65a8af1737d33","sha512_sri":"sha512-/SfjAMFPDzc1qiS+FBKqvUN6X47aY3ISyWPoOg6Vf8kDs+8vFGIp06IWye8birDFkcmQPummrTG6uVf7eHPsKA=="}}],"evidence_files":[{"sha256":"4f58c34cfd6196bc5f272509dfe74e27ef056726cabd887dc4cc11573da5e5b6","tlsh":"21a196a6156630198bb0ebe4c7175419f65be6632380c2d4fb9ca9981f7316483b2efc","path":"_compat.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tinkoff-cache-path/MAL-2026-12076.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}