{"schema_version":"1.8.0","id":"MAL-2026-12157","published":"2026-08-05T08:45:15Z","modified":"2026-08-05T10:05:57.661961489Z","summary":"Malicious code in bigops-chats (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (322310cb37baed38193c12087a25e40901a781467fc070c1bf078293ca8586be)\nOn require() of bigops-chats, index.js loads _helpers.js which assembles C2 hostnames via array split-join obfuscation (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, with a DNS-TXT fallback under sdk.dl.wel1.ru), fetches a platform-specific binary from those hosts without hash or signature verification, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd with stdio ignored. A stamp file at /tmp/.analytics_state suppresses re-runs. The staged filename mimics dotnet diagnostic tooling and the behavior is framed as analytics with an env-var opt-out. Hostnames are not publisher-controlled infrastructure and the delivered bytes are opaque and unverifiable.\n","affected":[{"package":{"name":"bigops-chats","ecosystem":"npm","purl":"pkg:npm/bigops-chats"},"versions":["35.9.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_helpers.js","sha256":"5d600e417520560be0f5617c6fb305db5894bab224b264eb120f640a5eae4a35","tlsh":"fda1779a166670188bb0d7e8c7274816f65bf6633780c2c4fb6ca5980f761248372efc"}],"package_integrity":[{"filename":"bigops-chats-35.9.6.tgz","hashes":{"sha1":"dcab52a5f2fb28e698654642b999b64d8fb89664","sha512_sri":"sha512-7f6w9bxt0hSIeXXwqgqHaiRjHwTrBSPF5TtXGw9E3AqIKjmC6eDqyipag3hHBhh/kr0sRbkJxRkmDEjtNind3Q=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-chats/MAL-2026-12157.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-chats/v/35.9.6"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014403","import_time":"2026-08-05T09:28:06.895173041Z","modified_time":"2026-08-05T08:45:15Z","sha256":"322310cb37baed38193c12087a25e40901a781467fc070c1bf078293ca8586be","source":"amazon-inspector","versions":["35.9.6"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}