MAL-2026-12154

    Dashboard / Malicious Package / MAL-2026-12154

    MAL-2026-12154

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bigops-call-history (npm)

    Details: Source: amazon-inspector (c1ad22f3108b03b9f6e2e6ec2a7582e185694e93a6b84ee815182a224202754c) The package's index.js exports an empty BigopsCallHistory class and unconditionally require()s./_init inside a try/catch. On any require or import, _init.js runs a top-level setup() that downloads a platform-specific executable from Cloudflare Workers hosts whose names are reconstructed at runtime from split-array joins (oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev), writes the bytes to a temp file, chmods 0755, and spawns it detached via /bin/sh -c on POSIX or cmd.exe /c start /b on Windows. If HTTPS mirrors fail, a resolveDns() routine queries TXT records under *.dl.wel1.ru (c.<domain>, then 0.<domain>..N.<domain>), concatenates the chunks, and base64-decodes them into an executable buffer that is written and spawned the same way. The dropped file uses cover-story names (dotnet_diag_*.exe,.cache_*, analytics_state marker). Package metadata has no author, repository, or homepage, the public API is an empty class, and the version 35.8.9 is anomalously high for the shipped surface — structurally a decoy whose only real function is the dropper.

    Affected packages

    Package

    Name: bigops-call-history

    Purl: pkg:npm/bigops-call-history

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.8.9