{"schema_version":"1.8.0","id":"MAL-2026-12164","published":"2026-08-05T08:44:52Z","modified":"2026-08-05T10:06:00.894482248Z","summary":"Malicious code in bigops-eslint-config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (706ca9436cb98fc7516d9ccb15e8f55625b73575093bfe0933be786f54ba0667)\nThe package presents itself as an ESLint config but on require() unconditionally loads _vendor.js, which selects a platform-specific asset, fetches a binary via https.get from string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT chunked-base64 fallback to *.dl.wel1.ru (sdk/ext/pkg/net.dl.wel1.ru). The downloaded bytes are written to /var/tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmodded 0755, and spawned detached via cp.spawn('/bin/sh', ['-c', fp+' &'], {detached:true}).unref(). Endpoint strings are assembled from array joins to evade static inspection; a sibling lib/telemetry.js uses require('child_' + 'process') and fs['chmod'+'Sync'] to further hide the sinks. The package name and 'environment config reader' description are unrelated to this behavior. No hash/signature verification, no version pinning, and the hosts are anonymous mutable infrastructure — arbitrary attacker code runs on the installer's host on import.\n","affected":[{"package":{"name":"bigops-eslint-config","ecosystem":"npm","purl":"pkg:npm/bigops-eslint-config"},"versions":["35.1.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"25c168dcc6fd166adb190a64ce3e2938a74617783f268c092f24b801c7b007fc","tlsh":"c8b1b86a05a630094b70dbe4c7175415f65bf6637380c194fb9ca9880fb722482f2efc"}],"package_integrity":[{"filename":"bigops-eslint-config-35.1.9.tgz","hashes":{"sha1":"abfe9cb66959f1c73ec534bccbb62735f9e4e77a","sha512_sri":"sha512-b1lwSy+YdLRwPhQq2yOoocn15mTUOWiLW/a9ye+MIOeu5+VcAfLP0Awcy/2GCyoDyORCPtZHI6UvqL6Ar9q18A=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-eslint-config/MAL-2026-12164.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-eslint-config/v/35.1.9"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014400","import_time":"2026-08-05T09:28:06.5476086Z","modified_time":"2026-08-05T08:44:52Z","sha256":"706ca9436cb98fc7516d9ccb15e8f55625b73575093bfe0933be786f54ba0667","source":"amazon-inspector","versions":["35.1.9"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}