{"schema_version":"1.8.0","id":"MAL-2026-13234","published":"2026-08-05T15:36:04Z","modified":"2026-08-05T16:50:04.995879765Z","summary":"Malicious code in bigops-procedure-player (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4e28923577eff8eba09d7ebbd941220727c1851cf46ef25f4de8960070ad33bb)\nOn require(), index.js loads _loader.js, which reconstructs delivery hostnames at runtime via array.join(\"\") (e.g. oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev) and fetches an OS-specific binary via https.get. A fallback path assembles the payload from base64 chunks in DNS TXT records under *.dl.wel1.ru (a count record at c.<domain> and per-chunk records at <i>.<domain>). The received bytes are written to /var/tmp/.cache_<hex> on Unix or %TEMP%\\dotnet_diag_<hex>.exe on Windows, chmod'd 755 via a string-concatenated fs[\"chmod\"+\"Sync\"], and executed detached via cp.spawn(\"/bin/sh\", [\"-c\", fp+\" &\"]) or the cmd equivalent. Filenames masquerade as system cache/diagnostic artifacts and the delivery hosts are unrelated to the package publisher. lib/telemetry.js contains a duplicate fetch->chmod 755->detached-spawn dropper body that is not reached from index.js in this version but mirrors the same loader shape.\n","affected":[{"package":{"name":"bigops-procedure-player","ecosystem":"npm","purl":"pkg:npm/bigops-procedure-player"},"versions":["35.8.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_loader.js","sha256":"96e8439a645c98a4c4af75a2f140a3b0829f2ac5b61bb312b6736b628fd7c80e","tlsh":"f1a1959a166a70194bb0abe08717482af65be66337c0c2c4f75ca9885f735248371dfc"},{"path":"lib/telemetry.js","sha256":"8488b20b88a566462a6b923a1eb50e84a1ec8e40a2c858ca6e493b46fea15616","tlsh":"c3835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bigops-procedure-player-35.8.2.tgz","hashes":{"sha1":"c67e30743bb7ad5312715f4664bcdcd9c92befc5","sha512_sri":"sha512-4HQBEEfM99psOQw2vMJcV5eEEuYPWSiH7wa8SZ0g3NB/KU4gDJZ2/t+1/0Etf4hLCWoP1NqdAL5Sp31i73hInQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-procedure-player/MAL-2026-13234.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-procedure-player/v/35.8.2"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015761","import_time":"2026-08-05T16:13:42.327151192Z","modified_time":"2026-08-05T15:36:04Z","sha256":"4e28923577eff8eba09d7ebbd941220727c1851cf46ef25f4de8960070ad33bb","source":"amazon-inspector","versions":["35.8.2"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}