MAL-2026-13525Malicious code in bigops-security (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | bigops-security | 35.8.8 |
{"modified":"2026-08-07T12:24:34Z","published":"2026-08-07T12:24:34Z","schema_version":"1.7.4","id":"MAL-2026-13525","summary":"Malicious code in bigops-security (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f4eccfe477123e2d048f10c141165dec00f0ce2bfe28b7b9611a189fc63f0384)\nOn require('bigops-security'), index.js loads _bridge.js which downloads a platform-specific executable from obfuscated Cloudflare Workers hosts (oob-worker.cf10{0..3}-*.workers.dev) with a DNS-TXT chunked-base64 fallback via *.dl.wel1.ru subdomains. Destination hostnames are reconstructed at runtime from split string arrays (e.g. ['sdk','.dl.','wel1.','ru'].join('')) rather than appearing as plain literals. The fetched bytes are written to /tmp or %TEMP% under disguised names such as dotnet_diag_<hex>.exe and.cache_<hex>, chmod 755'd, and detach-spawned via spawn('/bin/sh',...) or spawn('cmd',...) at _bridge.js:121-127. Cover-story identifiers (\"analytics\", \"telemetry\", \"CDN\", \"Respect opt-out\") frame the code as benign while the actual behavior is fetch-and-execute of an opaque binary from author-controlled infrastructure. No native-build purpose is present in the tarball; the package advertises itself as a security module.\n","affected":[{"package":{"ecosystem":"npm","name":"bigops-security"},"versions":["35.8.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"8744adb7c670453f85aa1ddf3958f0aac76407860f14adc65e685bcee2c6ec18","tlsh":"5ab1a79616aa711987b0d7e487174416f69ae7633380c6d8fb6ca8885f73128c3b1dfc"}],"package_integrity":[{"filename":"bigops-security-35.8.8.tgz","hashes":{"sha1":"6f4edd0c585317035ebf5bb09715892132240aad","sha512_sri":"sha512-zpV3iSE91mk6LFCI44JVnqW536wB9WYDRiir2NSWqtprCCbDio5hBaFwqgVER2Y9EKfXEPuF0l0jXtSil3n+Aw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-security/v/35.8.8"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016968","import_time":"2026-08-07T12:51:20.183407555Z","modified_time":"2026-08-07T12:24:34Z","sha256":"f4eccfe477123e2d048f10c141165dec00f0ce2bfe28b7b9611a189fc63f0384","source":"amazon-inspector","versions":["35.8.8"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0