statist-browser-typed-client-sme.salary.web.metrics@20.5.9
Malicious code in statist-browser-typed-client-sme.salary.web.metrics (npm)
Analysis
Package is a trojanized binary dropper. On require(), it detects the platform and architecture, then downloads a binary payload from Cloudflare Workers C2 endpoints (oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev) via HTTPS GET /pkg/package (or platform-specific paths). It has a DNS TXT-based fallback channel via c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<hex> on Linux/macOS or %TEMP%\dotnet_diag_<hex>.exe on Windows, made executable, and spawned as a detached background process (cmd.exe /c start /b on Windows, /bin/sh -c on Linux). The package has no repository and no lifecycle scripts — the dropper runs automatically when the module is required.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 10:12 AM
- analyzed
- Aug 2, 2026, 10:15 AM
Related advisories
- tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks@20.4.7
- @bobfrankston/rmfmail@1.2.211
- beaver-ui-icon-lock@12.2.3
- beaver-ui-card-large@9.6.3
- akamaijs@1.0.1
- postcss-animate-css-vars@2.0.3
- log-min@1.0.13
- streak-metrics-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.