{"schema_version":"1.8.0","id":"MAL-2026-12161","published":"2026-08-05T08:46:04Z","modified":"2026-08-05T10:05:59.095310544Z","summary":"Malicious code in bigops-communication-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (81c94eee2da1d74fc50236452fc79165eb1183ce0bb874a62a9a7985b6e77206)\nOn require() of the package, index.js loads _platform.js which invokes init() at module top level. init() downloads an opaque binary from Cloudflare Workers subdomains (oob-worker.cf102-baf.workers.dev, cf100-416, cf103-070, cf99-9b3.workers.dev) whose hostnames are reconstructed at runtime via array-join to evade static string scanners, with a DNS TXT covert channel (chunked base64 payload retrieved from sdk.dl.wel1.ru) as fallback. The fetched bytes are written to /tmp or %TEMP% under names impersonating.NET diagnostic tools (dotnet_diag_<tag>.exe,.cache_<tag>), chmod 0755 on Unix, then spawned detached via /bin/sh -c or cmd.exe start /b with stdio ignored. Anti-analysis logic aborts execution if DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK are set and stamps /tmp/.analytics_state to skip re-execution for ~22438 seconds, framing the dropper as telemetry. There is no legitimate purpose for a require()-time fetch-and-execute of an unpinned, unverified binary from anonymous Workers hosts with runtime host reconstruction and a DNS-TXT payload channel.\n","affected":[{"package":{"name":"bigops-communication-client","ecosystem":"npm","purl":"pkg:npm/bigops-communication-client"},"versions":["35.8.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_platform.js","sha256":"b5abc7815482d1233705fe6ac602f0cfe50fcca26394ed9d45066986597d1591","tlsh":"afa1b65612aa70194bb0e7e4cb1b8419f55bf66337808294fb9ca5d45f7342483b2efc"}],"package_integrity":[{"filename":"bigops-communication-client-35.8.8.tgz","hashes":{"sha1":"545e6574625dd35eea3fee3226da246a634f5c30","sha512_sri":"sha512-tn+Asiu3UiPKfhkty5x7iY1e8OlequfTFFYmaTOwrHEuIaX10FlxJ7qZqWDSQZeDFHXam7XukSgcHd/EZbp8hA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-communication-client/MAL-2026-12161.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-communication-client/v/35.8.8"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014408","import_time":"2026-08-05T09:28:07.591391241Z","modified_time":"2026-08-05T08:46:04Z","sha256":"81c94eee2da1d74fc50236452fc79165eb1183ce0bb874a62a9a7985b6e77206","source":"amazon-inspector","versions":["35.8.8"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}