-= Per source details. Do not edit below this line.=-
The package's main entry (index.js) requires./setup at load time. setup.js assembles obfuscated Cloudflare Workers hostnames via array-join concatenation (e.g. oob-worker.cf99-9b3.workers.dev, cf103-070/cf102-baf/cf101-adf.workers.dev) with a DNS TXT fallback resolving through tin.dl.well1.site / tina.dl.well1.site / ldr.dl.well1.site / win.dl.well1.site, downloads a platform-specific binary payload with no hash or signature verification, writes it to /tmp or %TEMP% under a disguised filename, chmods it to 0755, and spawns it detached via cp.spawn('/bin/sh', ['-c', fp + ' &'], {detached:true}) (or cmd on Windows). A second module lib/telemetry.js (framed as an 'Analytics SDK') bundles the same dropper primitives with additional evasion (require('child_' + 'process'), fs['chmod' + 'Sync']). The remote destinations, obfuscated hostname assembly, and executed payload are unrelated to the package's stated 'features banner' purpose.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-05T01:39:31.804872839Z",
"modified_time": "2026-08-05T01:32:48Z",
"sha256": "9792640803b7c90320c995d134baefcd36a52037d1947a3c0262c9d9e5ada168",
"id": "IN-MAL-2026-011500",
"versions": [
"20.2.4"
],
"source": "amazon-inspector"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-kMiz576PHa42g4Ug6KayEa1avG1pGIDiO49x6y0lsFJiQ/pssbHcFkkA/BkRFJkyQnYmaA3GgMkS36jWjW6HKw==",
"sha1": "111bd6bf729f8bd79ba27510b84247041a3e2489"
},
"filename": "tinkoff-boxy-desktop-features-banner-20.2.4.tgz"
}
],
"evidence_files": [
{
"path": "setup.js",
"sha256": "f71fdab909fa0f2cca8c75fb744f95542642c76b12e11677aed022ead8e96929",
"tlsh": "b5a1a6aa116670194b70dbe4c7175419f557f66373808294fbaca5981ff322483b2efc"
},
{
"path": "lib/telemetry.js",
"sha256": "837fc064b623569160b8415e9c2025e9031bfc4917e35e4b6e17eddf4276ca1e",
"tlsh": "49835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tinkoff-boxy-desktop-features-banner/MAL-2026-12048.json"