tinkoff-pfpa-tools@20.3.1
Malicious code in tinkoff-pfpa-tools (npm)
Analysis
tinkoff-pfpa-tools@20.3.1 is a trojanized SDK that, when required, fingerprints the host OS and architecture, then downloads a binary payload from one of four Cloudflare Workers C2 endpoints (oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev) via HTTPS GET /pkg/package (or platform-specific paths). It also uses a DNS TXT-based fallback channel through c[.]tin[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<hex> (or %TEMP%\dotnet_diag_<hex>.exe on Windows) and executed as a detached background process. The package has no repository, no README, and no documented purpose — it is a multi-stage binary downloader.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 05:55 PM
- analyzed
- Aug 2, 2026, 05:56 PM
Related advisories
- statist-statist-core@20.9.9
- tinkoff-boxy-desktop-features-banner@20.2.4
- tinkoff-statist-browser-typed-client-mb.reliability.android.events@20.5.4
- tinkoff-component-infopanel@20.8.3
- tinkoff-statist-browser-typed-client-cardsmobile.events.promotest@20.8.7
- statist-browser-typed-client-hra.workplacer.events@20.9.1
- twork-data-services-product-design-data@20.1.5
- tinkoff-pfp-integration-mobile-slider-icons@20.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.