MAL-2026-13494Malicious code in bigops-telephony-mock (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | bigops-telephony-mock | 35.7.2 |
{"modified":"2026-08-07T12:11:49Z","published":"2026-08-07T12:11:49Z","schema_version":"1.7.4","id":"MAL-2026-13494","summary":"Malicious code in bigops-telephony-mock (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ccbd56ae20f9cc922c12df25456654a649c9bbc963aae4fa95e027f97628c45b)\nRequiring the package (index.js ->./setup) triggers setup.js, which reconstructs destination hostnames from split string fragments (e.g. oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, downloads a platform-specific binary via https.get, writes it to a disguised path under /tmp or %TEMP% (names such as analytics_state, dotnet_diag_*.exe,.cache_*), fs.chmodSync's it to 0755, and cp.spawn's it detached via /bin/sh -c '<file> &' or cmd.exe /c start /b. No version pin, no hash or signature verification, and destinations are assembled at runtime to defeat static inspection; child_process itself is required as \"child_\" + \"process\" in lib/telemetry.js. A second copy of the same download->base64-decode->chmod 755->spawn /bin/sh loader is bundled under lib/telemetry.js (approximately 81KB) framed as a telemetry SDK. The behavior fires on any require()/import of the package, gated only by an opt-out env var and a TTL marker file, so a normal npm install followed by loading the module causes attacker-controlled code to execute on the installer's machine.\n","affected":[{"package":{"ecosystem":"npm","name":"bigops-telephony-mock"},"versions":["35.7.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"setup.js","sha256":"354e3b3034f3f0752ffdbfeae03cfb6da5938b19b54f751cfc3f192aeb580a35","tlsh":"9aa1a79a1266b1188fb0abe4c71b8816f61bf2a33781c284fb5c65845f735148372efc"},{"path":"lib/telemetry.js","sha256":"7f71a0f07b9f72570746aaacb191fb3d313fa373cef63b3ad65266b6d3aa49e4","tlsh":"5e835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bigops-telephony-mock-35.7.2.tgz","hashes":{"sha1":"0598b325f3496cb29ab1f535148f4f4601cd27f9","sha512_sri":"sha512-pYwY8e7fOrRPQdrcHtxHpeauaR0uI9cDP0BwZdDAmfP5tPxkmSUy8pwZh+Ncy29Awv6AsY2MvLTFkA2IufFCyg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-telephony-mock/v/35.7.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016878","import_time":"2026-08-07T12:23:25.447470807Z","modified_time":"2026-08-07T12:11:49Z","sha256":"ccbd56ae20f9cc922c12df25456654a649c9bbc963aae4fa95e027f97628c45b","source":"amazon-inspector","versions":["35.7.2"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0