MAL-2026-12160
Dashboard / Malicious Package / MAL-2026-12160
MAL-2026-12160
Summary: Malicious code in bigops-cobrowsing-client (npm)
Details: Source: amazon-inspector (25ce2f0f7a7411a7bfedb5d07449d26620388d3936e5951883e52463de01ef50) On require() of this package, index.js loads _shim.js which triggers an async payload that fetches a platform-specific binary from obfuscated Cloudflare Workers hostnames (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev), writes it to /var/tmp or %TEMP% under a masquerading name (.cache_<rand> on Unix, dotnet_diag_<rand>.exe on Windows), chmods it 0o755, and spawns it detached via /bin/sh or cmd.exe. Both the C2 hostnames and a DNS-TXT fallback channel (chunked base64 payload retrieved from TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru) are reconstructed at runtime via.join('') of split string fragments to evade static string detection. The DNS-TXT fallback reads a chunk count from c.<domain> and iterates <n>.<domain> TXT queries, base64-decoding the concatenation into an executable buffer that is written to disk and run. The package advertises itself as a cobrowsing client, but the shipped code contains no cobrowsing functionality — only the dropper.
Affected packages
Package
Name: bigops-cobrowsing-client
Purl: pkg:npm/bigops-cobrowsing-client
Affected ranges
Type: N/A
Events:
