MAL-2026-12689

    Dashboard / Malicious Package / MAL-2026-12689

    MAL-2026-12689

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in delivery-ci-validate-tinkoff-fb (npm)

    Details: Source: amazon-inspector (1c2b95894675a32af7552c62bb8cd49bbd1d69f64d2685118ed2fede54c0b1a0) The package presents itself as a CI validation helper but `index.js` calls `require('./_adapter')` on import, causing _adapter.js to run automatically. _adapter.js assembles C2 hostnames at runtime via `.join('')` over split fragments (resolving to `oob-worker.cf10{0..3}-*.workers.dev` with a `*.dl.wel1.ru` DNS-TXT base64 fallback), downloads a platform-specific binary with no version pin or integrity check, writes it to a hidden staging path (`/var/tmp/.cache_<hex>` on Unix, `%TEMP%/dotnet_diag_<hex>.exe` impersonating a Microsoft diagnostic tool on Windows), `chmod 0755`s it, and spawns it detached via `/bin/sh -c... &` or `cmd.exe /c start /b`. A filesystem cooldown marker (`analytics_state`) and telemetry-style naming are used as cover. The exported `validate()` function is a trivial stub unrelated to the dropper.

    Affected packages

    Package

    Name: delivery-ci-validate-tinkoff-fb

    Purl: pkg:npm/delivery-ci-validate-tinkoff-fb

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.6.9