MAL-2026-12249Malicious code in tinkoff-pfp-block-mobile-panels (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | tinkoff-pfp-block-mobile-panels | * |
| npm | tinkoff-pfp-block-mobile-panels | 20.2.7 |
{"schema_version":"1.7.4","id":"MAL-2026-12249","published":"2026-08-05T08:57:00Z","modified":"2026-08-25T16:28:08.058126991Z","aliases":["GHSA-gp62-rq95-4fg5"],"summary":"Malicious code in tinkoff-pfp-block-mobile-panels (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7ba61172e292eb3f23c0077e187700932f461fc726674f5497030751138da2d3)\nOn require() of the package, _helpers.js selects a platform-specific binary path, downloads bytes from one of four hardcoded Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev) with DNS-based fallback via subdomains of well1.site (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site), writes the payload to /tmp or %TEMP% under a disguised name (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe. Host names and dangerous API names (child_process, chmodSync) are assembled at runtime from split strings via.join('') to evade static analysis. index.js unconditionally require('./_helpers'), so the dropper fires on any import of the package. A second dropper variant with the same shape ships in lib/telemetry.js (~81KB, currently unreferenced from index.js). Package name impersonates the Tinkoff brand and README references an 'internal tracker' to suggest insider legitimacy, consistent with a dependency-confusion lure targeting Tinkoff-adjacent developer workstations.\n\n## Source: ghsa-malware (9b9c5a116ce49fa3574574f437997f90db114b2d782ebf5b28b8d357b2ea0de3)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","affected":[{"package":{"name":"tinkoff-pfp-block-mobile-panels","ecosystem":"npm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["20.2.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"c7df17dc689caf15c0588d2ccc49209a53948c327b310d5abfaef32c790f4f42","tlsh":"03b1986612a6701d4bb0dbe5c7175419f65af663738082d4f79ca4885fb2124c2f2efc"},{"path":"lib/telemetry.js","sha256":"49fb124416f3f4fe9b6fd77e0d5e5dd7e0652704c8942678273a6b988cbc05b1","tlsh":"ab835056566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"},{"path":"package.json","sha256":"e4254a41650837386341acf77960510b45853d740d02ac8388561bd232ab990e","tlsh":"97c012124a21697310b449604c62525677720f1e6128dc06b7b77014509456a19aa336"}],"package_integrity":[{"filename":"tinkoff-pfp-block-mobile-panels-20.2.7.tgz","hashes":{"sha1":"a11b321f0248bb0db676b973754048a941d18b6a","sha512_sri":"sha512-LpYtfHrn5hNuwb1zGbFB7Vzer/TcbgPt+TOj+utAW38tgFXdLKgPZYeaBKAnA+85auzAh6Sg7oiNEUOfArOTYg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tinkoff-pfp-block-mobile-panels/v/20.2.7"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gp62-rq95-4fg5"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014483","import_time":"2026-08-05T09:28:17.258427275Z","modified_time":"2026-08-05T08:57:00Z","sha256":"7ba61172e292eb3f23c0077e187700932f461fc726674f5497030751138da2d3","source":"amazon-inspector","versions":["20.2.7"]},{"id":"GHSA-gp62-rq95-4fg5","import_time":"2026-08-25T16:26:05.033895984Z","modified_time":"2026-08-25T15:53:26Z","ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"9b9c5a116ce49fa3574574f437997f90db114b2d782ebf5b28b8d357b2ea0de3","source":"ghsa-malware"}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0