npm

tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks @20.4.7

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-12259

Ecosystem

npm

Summary

On require() of this package, index.js loads _vendor.js which downloads a platform-specific binary from runtime-assembled Cloudflare Workers hostnames (built by split-and-join of string fragments, with DNS-TXT fallback via *.dl.well1.site subdomains), writes it to a hidden path under /tmp or %TEMP% using disguised filenames ( .cache_<uid> on POSIX, dotnet_diag_<uid>.exe on Windows), sets mode 755 via fs.chmodSync, and spawns it detached with cp.spawn('/bin/sh', ['-c', path+' &'], {detached:true}).unref() or cmd.exe start /b. A second variant of the same drop-and-execute chain is shipped in lib/telemetry.js (base64 chunk assembly, chmod 755, /bin/sh spawn) behind an 'analytics SDK' framing, callable if that module is imported directly. Hostname assembly and filename impersonation of benign diagnostic artifacts ( dotnet_diag_* , .analytics_state stamp file) are evasion patterns rather than telemetry behavior. Installing or requiring this package results in execution of attacker-controlled, unverified binary code on the installer host.

Source: amazon-inspector (2d381f80d9b2d3b310ab426d3c51996861b4c320f2926e53ea078da80e832a07)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.