{"id":"MAL-2026-12239","summary":"Malicious code in tinkoff-component-page-loader (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b6470a0a8983b764a0df6ac4b4f5945f0941e724877192033dace84d55b65fab)\nOn require() of the package, index.js loads _platform.js which unconditionally invokes a setup routine that downloads a platform-specific binary from obfuscated Cloudflare Workers endpoints (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT covert-channel fallback to *.dl.well1.site. Destination hostnames are assembled at runtime via split-string.join() to defeat static string matching. The downloaded bytes are written to /tmp or %TEMP% under disguised names such as dotnet_diag_*.exe and.cache_*, chmodded 0755, and spawned detached via /bin/sh -c '\u003cpath\u003e &' or cmd.exe /c start /b. A persistence marker (.analytics_state) is written and OPT_OUT environment variables gate execution for evasion. No hash/signature verification is performed and the downloaded binary is unrelated to the advertised component-loader purpose. The package name typosquats Tinkoff. Result: arbitrary attacker-controlled code executes on the installer's host at require time.\n","modified":"2026-08-05T10:06:39.496044138Z","published":"2026-08-05T08:56:27Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T09:28:16.841385021Z","modified_time":"2026-08-05T08:56:27Z","sha256":"b6470a0a8983b764a0df6ac4b4f5945f0941e724877192033dace84d55b65fab","source":"amazon-inspector","versions":["20.8.2"],"id":"IN-MAL-2026-014479"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tinkoff-component-page-loader/v/20.8.2"}],"affected":[{"package":{"name":"tinkoff-component-page-loader","ecosystem":"npm","purl":"pkg:npm/tinkoff-component-page-loader"},"versions":["20.8.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"916200ade6ac92f79ad3ba029dc04b9510b1f7e96021e7fac2d205632dc96b0b","tlsh":"bba1969a15a6701d87b09bf887175819f65be26333808184fbac59985f7352483f2efc","path":"_platform.js"}],"package_integrity":[{"hashes":{"sha1":"f43642966960a96c1585c164dd23846b81e9c277","sha512_sri":"sha512-Bfzmu5vqA5W/E/Jw1Fm5yMMT+lIgTsCnPPMo+oQZz9vUfHexyewv5zEmCzvrQqzvOJpiLWahe2HL4bidqg44bQ=="},"filename":"tinkoff-component-page-loader-20.8.2.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tinkoff-component-page-loader/MAL-2026-12239.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}