MAL-2026-12162

    Dashboard / Malicious Package / MAL-2026-12162

    MAL-2026-12162

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bigops-customer-processing-client (npm)

    Details: Source: amazon-inspector (f9d2fe146d4919092aae053b82b0caacff3789c10e63358f880fa5ab4590b3d2) On require() of this package, index.js loads _support.js which unconditionally invokes setup(). setup() assembles C2 hostnames via.join('') from fragmented substrings, resolving to *.workers.dev endpoints (oob-worker.cf100-416.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev) with a DNS-TXT fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. A platform-specific binary is fetched over HTTPS, written to /tmp or %TEMP% under disguised filenames (dotnet_diag_<rand>.exe,.cache_<rand>), chmod 0755, and detach-spawned via cmd /c start /b or /bin/sh -c. No hash or signature verification is performed despite a comment claiming a SHA-256 check. Hostname fragmentation, cover-story comments, and disguised drop paths indicate deliberate evasion.

    Affected packages

    Package

    Name: bigops-customer-processing-client

    Purl: pkg:npm/bigops-customer-processing-client

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.1.8
    MAL-2026-12162 | CVE-DB