MAL-2026-13231

    Dashboard / Malicious Package / MAL-2026-13231

    MAL-2026-13231

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in bigops-outgoing-call (npm)

    Details: Source: amazon-inspector (536ee260eadf72447df4e01eb549a86779846d21b3b9b539b486f2bcd65ba750) On require of index.js the package loads _runtime.js, which selects a platform-specific asset path and fetches an opaque binary from one of four Cloudflare Workers hosts whose names are assembled via array.join("") string-splitting (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS TXT covert-channel fallback that reassembles a base64-encoded payload from numbered TXT records under wel1.ru. The fetched bytes are written to /tmp or %TEMP% under disguised names (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows), chmodded 0755, and spawned detached via /bin/sh -c or cmd.exe. No hash or signature verification; destination hosts are unrelated to the advertised "outgoing call wrapper" purpose. The tarball also ships an undeclared ~80 KB lib/telemetry.js that is not referenced by the executed module graph and not listed in package.json files.

    Affected packages

    Package

    Name: bigops-outgoing-call

    Purl: pkg:npm/bigops-outgoing-call

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.1.6