MAL-2026-12161
Dashboard / Malicious Package / MAL-2026-12161
MAL-2026-12161
Summary: Malicious code in bigops-communication-client (npm)
Details: Source: amazon-inspector (81c94eee2da1d74fc50236452fc79165eb1183ce0bb874a62a9a7985b6e77206) On require() of the package, index.js loads _platform.js which invokes init() at module top level. init() downloads an opaque binary from Cloudflare Workers subdomains (oob-worker.cf102-baf.workers.dev, cf100-416, cf103-070, cf99-9b3.workers.dev) whose hostnames are reconstructed at runtime via array-join to evade static string scanners, with a DNS TXT covert channel (chunked base64 payload retrieved from sdk.dl.wel1.ru) as fallback. The fetched bytes are written to /tmp or %TEMP% under names impersonating.NET diagnostic tools (dotnet_diag_<tag>.exe,.cache_<tag>), chmod 0755 on Unix, then spawned detached via /bin/sh -c or cmd.exe start /b with stdio ignored. Anti-analysis logic aborts execution if DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK are set and stamps /tmp/.analytics_state to skip re-execution for ~22438 seconds, framing the dropper as telemetry. There is no legitimate purpose for a require()-time fetch-and-execute of an unpinned, unverified binary from anonymous Workers hosts with runtime host reconstruction and a DNS-TXT payload channel.
Affected packages
Package
Name: bigops-communication-client
Purl: pkg:npm/bigops-communication-client
Affected ranges
Type: N/A
Events:
