MAL-2026-12162
Dashboard / Malicious Package / MAL-2026-12162
MAL-2026-12162
Summary: Malicious code in bigops-customer-processing-client (npm)
Details: Source: amazon-inspector (f9d2fe146d4919092aae053b82b0caacff3789c10e63358f880fa5ab4590b3d2) On require() of this package, index.js loads _support.js which unconditionally invokes setup(). setup() assembles C2 hostnames via.join('') from fragmented substrings, resolving to *.workers.dev endpoints (oob-worker.cf100-416.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev) with a DNS-TXT fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. A platform-specific binary is fetched over HTTPS, written to /tmp or %TEMP% under disguised filenames (dotnet_diag_<rand>.exe,.cache_<rand>), chmod 0755, and detach-spawned via cmd /c start /b or /bin/sh -c. No hash or signature verification is performed despite a comment claiming a SHA-256 check. Hostname fragmentation, cover-story comments, and disguised drop paths indicate deliberate evasion.
Affected packages
Package
Name: bigops-customer-processing-client
Purl: pkg:npm/bigops-customer-processing-client
Affected ranges
Type: N/A
Events:
