{"id":"MAL-2026-12253","summary":"Malicious code in tinkoff-statist-browser-typed-client-art.apps.reporegistry (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d935ce8eda3349f3633b3ab3c55baa492821164fbdb291bc942863d3aac4d4c1)\nOn require of the package, _adapter.js executes a top-level bootstrap that downloads a platform-specific binary from hardcoded Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, cf99-9b3.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev) with DNS-TXT fallback to tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site. The destination hostnames and the child_process module name are assembled at runtime via array.join to evade static inspection. The fetched bytes are written to /var/tmp/.cache_\u003crand\u003e on Unix or %TEMP%\\dotnet_diag_\u003crand\u003e.exe on Windows, chmod'd to 0755, and detach-spawned via /bin/sh -c or cmd /c start. A second module, lib/telemetry.js, contains the same dropper pattern (base64 chunk assembly, string-concatenated fs.chmodSync, cp.spawn('/bin/sh', ['-c', filePath + ' &'], {detached:true})) as a staged/redundant payload. Package naming and the analytics-SDK framing do not match the observed behavior, which is a runtime fetch-and-execute of attacker-controlled bytes on the installer's host.\n","modified":"2026-08-05T10:06:45.539980513Z","published":"2026-08-05T09:02:22Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014519","import_time":"2026-08-05T09:28:21.548317614Z","modified_time":"2026-08-05T09:02:22Z","sha256":"d935ce8eda3349f3633b3ab3c55baa492821164fbdb291bc942863d3aac4d4c1","source":"amazon-inspector","versions":["20.9.7"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tinkoff-statist-browser-typed-client-art.apps.reporegistry/v/20.9.7"}],"affected":[{"package":{"name":"tinkoff-statist-browser-typed-client-art.apps.reporegistry","ecosystem":"npm","purl":"pkg:npm/tinkoff-statist-browser-typed-client-art.apps.reporegistry"},"versions":["20.9.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_adapter.js","sha256":"857e2279bfdce4a0861be162742e27a03370db701c215d13ada5676361cd4f9d","tlsh":"bab1b4aa066570194b70dbe5ca179415f65af6537380c194fbaca99c0fb212483f2efc"},{"path":"lib/telemetry.js","sha256":"c6d7c3d30552c41875e964c02716939ed9a05588880f7b8e50febd11094d6686","tlsh":"78835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"tinkoff-statist-browser-typed-client-art.apps.reporegistry-20.9.7.tgz","hashes":{"sha512_sri":"sha512-zg6p2lJMWCMFBkkQVEpn4cfVR9vBj8rf/OjONgW96+nHBEoctdb1eT3XuqjCvZ9OasMDA61YyFumyQSjG0oi9g==","sha1":"a84840f2ca7f770a2ebfb5cae5bdcafd0b2d9618"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tinkoff-statist-browser-typed-client-art.apps.reporegistry/MAL-2026-12253.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}