{"schema_version":"1.8.0","id":"MAL-2026-13226","published":"2026-08-05T15:37:50Z","modified":"2026-08-05T16:50:01.228945602Z","summary":"Malicious code in bigops-nitro-events-table (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6d222994e1816e63b4047f5396bbfda8d6d2ccd6bbc840da4872aa026f879525)\nThe package's index.js requires./_shim on load. _shim.js selects a platform-specific payload path, fetches an executable via https.get from one of three Cloudflare Workers hostnames reconstructed from string-split arrays joined at runtime (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT base64 fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The downloaded binary is written to /var/tmp/.cache_<rand> on Unix or %TEMP%/dotnet_diag_<rand>.exe on Windows, chmodded 0755, and spawned detached via /bin/sh -c '<path> &' or cmd /c start. Payload filenames impersonate benign diagnostics artifacts, the User-Agent is spoofed as 'node-fetch/2.6', a.analytics_state lock file is used, and the payload is skipped when DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env vars are set — an evasion to blend in as telemetry and avoid privacy-conscious hosts. The package is advertised as a trivial pub/sub adapter and has no legitimate need to fetch or execute a native binary.\n","affected":[{"package":{"name":"bigops-nitro-events-table","ecosystem":"npm","purl":"pkg:npm/bigops-nitro-events-table"},"versions":["35.4.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_shim.js","sha256":"d81068ad8fcad23f757cfd2ec5a005d26ac8629a5eadacd749ef77873c7abb61","tlsh":"52a1959a1266301d8bb0ebe08b175419f65af6633380c294fb5c69d85fb212483b2dfc"}],"package_integrity":[{"filename":"bigops-nitro-events-table-35.4.2.tgz","hashes":{"sha1":"98cb5fcf5aa434f2005c56fccd050c851da17fd4","sha512_sri":"sha512-nS8pZRZcgWKAgtSzYFKUNlDQ/agflkyrFbToDPep06xvpvgqfwMvaTrCvGU7jYSuTLTm7Vv/0d/o5jF42lpKPg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-nitro-events-table/MAL-2026-13226.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-nitro-events-table/v/35.4.2"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015772","import_time":"2026-08-05T16:13:43.516089014Z","modified_time":"2026-08-05T15:37:50Z","sha256":"6d222994e1816e63b4047f5396bbfda8d6d2ccd6bbc840da4872aa026f879525","source":"amazon-inspector","versions":["35.4.2"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}