tinkoff-boxy-mobile-documents@20.1.7
Malicious code in tinkoff-boxy-mobile-documents (npm)
Analysis
Combosquat package impersonating a mobile-documents SDK. On require(), _platform.js fingerprints the OS/architecture (linux_x64, darwin, win32) and downloads a platform-specific binary payload from Cloudflare Workers C2 endpoints (oob-worker.cf1*.workers[.]dev) via HTTPS. The downloaded payload is written to /tmp/.cache_<random> (or %TEMP%\dotnet_diag_<random>.exe on Windows) and executed as a detached background process that outlives the parent. A fallback DNS TXT-based C2 channel (c[.]tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, win[.]dl[.]well1[.]site) is used if the HTTPS download fails. The package has no repository, no lifecycle scripts in manifest, and no README — the payload runs purely through code evaluation at require time.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 05:11 PM
- analyzed
- Aug 2, 2026, 05:12 PM
Related advisories
- eventea-router@20.2.3
- statist-browser-typed-client-risktech.uwfrontantifraud.events@20.1.5
- shopping-shared-atom-mobile-cart-counter@20.6.6
- nxify-unic@20.3.2
- pfp-block-mobile-past-meetup-list@20.5.1
- pfp-forms-sme-sitebuilder@20.2.1
- statist-browser-typed-client-twork.tsales.nitro.metrics@20.6.2
- sme-rko-finance-front-shared-entity-groups-models@20.2.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.