tinkoff-statist-browser-typed-client-dwh.chimera.base @20.2.3
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12258
Ecosystem
npm
Summary
Requiring this package triggers _support.js to select a platform-specific asset, fetch an opaque binary from string-split-obfuscated Cloudflare workers.dev mirror hosts (assembled at runtime via.join('')) with a DNS-TXT chunked-base64 fallback channel on *.dl.well1.site, write the bytes to /var/tmp/.cache_<hex> on Unix or %TEMP%/dotnet_diag_<hex>.exe on Windows, chmod 0755, and detach-spawn the binary via /bin/sh -c or cmd.exe /c start /b. Destination hostnames are reconstructed from split fragments; dropped filenames impersonate a dotnet diagnostic tool or hidden cache; module comments and environment variables named DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK frame the code as analytics/telemetry as a cover story. The package name impersonates a Tinkoff-internal scope. Fetching and executing attacker-controlled bytes from non-publisher hosts at require time yields arbitrary code execution on the installer's host.
Source: amazon-inspector (e85e012cccc354c615a7d3fc6f753b676fa6f56e1053170a6e24f173ad930008)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.