tinkoff-component-infopanel@20.8.3
Malicious code in tinkoff-component-infopanel (npm)
Analysis
On require(), the package executes _platform.js which fingerprints the OS/architecture and downloads a platform-specific binary payload from a rotating set of Cloudflare Workers C2 domains (oob-worker[.]cf{99,100,101,102}-{9b3,416,adf,baf}.workers[.]dev). The binary is saved to /var/tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows) and spawned as a detached background process. If HTTPS download fails, the package falls back to DNS TXT-record-based payload reassembly via c[.]tin[.]dl[.]well1[.]site. The package has no repository, no lifecycle scripts, and its index.js is a minimal stub that immediately requires the dropper.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 05:53 PM
- analyzed
- Aug 2, 2026, 05:53 PM
Related advisories
- invest-module-cookie@20.8.2
- pfp-forms-independent-sme-glossary-anchor@20.4.4
- pfa-autotests-reporter@20.2.8
- tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci@20.1.2
- tinkoff-component-page-loader@20.8.2
- travel-core-utils-object@20.3.4
- twork-data-services-eacq-company-service-v2-api-v1-identifiers-crm@20.6.7
- deposits-overnight@20.8.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.