tinkoff-statist-browser-typed-client-dss.insurance.service@20.3.2
Malicious code in tinkoff-statist-browser-typed-client-dss.insurance.service (npm)
Analysis
Package tinkoff-statist-browser-typed-client-dss.insurance.service@20.3.2 is a trojanized combosquat package. On require(), it fingerprints the OS and architecture, then downloads a platform-specific binary from one of three Cloudflare Workers C2 hosts (oob-worker[.]cf101-adf[.]workers[.]dev, oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev) at path /pkg/package (or /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe per platform). If HTTPS download fails, it falls back to a DNS TXT-based data channel via c[.]tin[.]dl[.]well1[.]site and related domains (tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, win[.]dl[.]well1[.]site). The downloaded binary is written to /var/tmp/.cache_<random hex> (Unix) or %TEMP%\dotnet_diag_<random hex>.exe (Windows) and spawned as a detached background process. A marker file at /tmp/.analytics_state or %TEMP%\analytics_state prevents re-infection within ~21 seconds.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 05:10 PM
- analyzed
- Aug 2, 2026, 05:11 PM
Related advisories
- hubert-react-query@20.6.8
- deposits-overnight@20.8.5
- checkout-create-pos-order-am@20.9.5
- statist-browser-typed-client-nfs.grocery.mobile.events@20.3.3
- tinkoff-ui-action@20.5.7
- specials-obid-webpack@20.5.4
- tinkoff-pfp-atom-styles-tiles@20.2.8
- tinkoff-boxy-atom-text-link@20.5.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.