{"schema_version":"1.8.0","id":"MAL-2026-13242","published":"2026-08-05T15:34:32Z","modified":"2026-08-05T16:50:09.249383908Z","summary":"Malicious code in bigops-products-loans (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bee9ea7bc129d916b60d18e41425309fc1191d8d7688f1536d500f455f6d4c9a)\nOn require() of bigops-products-loans, index.js loads _init.js which downloads a platform-specific binary from obfuscated Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT record fallback under c.<domain> in *.dl.wel1.ru that base64-concatenates numbered TXT record parts into a binary payload. Destination hostnames are assembled by joining split string fragments to evade static detection. The fetched bytes are written to /tmp or %TEMP% under a disguised name (dotnet_diag_<rnd>.exe on Windows,.cache_<rnd> on Unix), chmodded 0755, and spawned detached via cmd.exe or /bin/sh -c with unref(). A TTL marker file suppresses re-execution and a DISABLE_TELEMETRY environment variable acts as an opt-out cover story. A second, parallel dropper implementation is bundled at lib/telemetry.js disguised as an analytics SDK (base64 chunk assembly, chmod 755, /bin/sh -c spawn of a decoded file path); it is not on the currently reachable require() path but ships in the tarball as a secondary payload runner.\n","affected":[{"package":{"name":"bigops-products-loans","ecosystem":"npm","purl":"pkg:npm/bigops-products-loans"},"versions":["35.6.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_init.js","sha256":"0fa26b21555300be8295b5cfb8886df21eb090d731b5caa50206d03f0f3fcf6d","tlsh":"d1a1746a157570184bb0dbe0c6175816f66bf6637280d299f79ca5980fb312483b2efc"},{"path":"lib/telemetry.js","sha256":"0a79ab7decc79271d0fdc081052d4a7b30d58e539dfbe58b6920675d9b58e76f","tlsh":"60835055566a242186b2b378df234107ff3685272642429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bigops-products-loans-35.6.4.tgz","hashes":{"sha1":"c1e3a0a339b766f6ec7c225982b542c6e75f6a6c","sha512_sri":"sha512-I4HnNSZI04+hVYraYL/cbPJ2KmesJWEP5JP+cF+cuSRSPnNVsv/h+LQshDZGvHQbKVHG4kOhpsBjG5yNu6skrw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-products-loans/MAL-2026-13242.json"}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-products-loans/v/35.6.4"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015751","import_time":"2026-08-05T16:13:40.206324485Z","modified_time":"2026-08-05T15:34:32Z","sha256":"bee9ea7bc129d916b60d18e41425309fc1191d8d7688f1536d500f455f6d4c9a","source":"amazon-inspector","versions":["35.6.4"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}