tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events@20.2.5
Malicious code in tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events (npm)
Analysis
Combosquat package impersonating a Tinkoff internal library. On require(), _loader.js immediately fingerprints the host (platform, arch, CPU count, memory, hostname, CI environment), then downloads a platform-specific binary payload from one of four Cloudflare Workers C2 endpoints (oob-worker[.]cf*.workers[.]dev/pkg/package*). If HTTPS fails, it falls back to DNS TXT-based C2 via c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<hex> (or %TEMP%\dotnet_diag_<hex>.exe on Windows), made executable, and spawned as a detached background process that outlives the parent. The package also probes for sandbox detection by querying _leitwacht.attached.local.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 03:16 PM
- analyzed
- Aug 2, 2026, 03:18 PM
Related advisories
- json-validator-utils@1.0.1
- layer2-sdk@1.0.1
- arb-kit@1.0.1
- wind_css@4.0.13
- unicode-colors@4.1.4
- hex-type@3.0.2
- farming-tools-12@4.68.54
- os-ulid-void@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.