MAL-2026-13242
Dashboard / Malicious Package / MAL-2026-13242
MAL-2026-13242
Summary: Malicious code in bigops-products-loans (npm)
Details: Source: amazon-inspector (bee9ea7bc129d916b60d18e41425309fc1191d8d7688f1536d500f455f6d4c9a) On require() of bigops-products-loans, index.js loads _init.js which downloads a platform-specific binary from obfuscated Cloudflare Workers subdomains (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT record fallback under c.<domain> in *.dl.wel1.ru that base64-concatenates numbered TXT record parts into a binary payload. Destination hostnames are assembled by joining split string fragments to evade static detection. The fetched bytes are written to /tmp or %TEMP% under a disguised name (dotnet_diag_<rnd>.exe on Windows,.cache_<rnd> on Unix), chmodded 0755, and spawned detached via cmd.exe or /bin/sh -c with unref(). A TTL marker file suppresses re-execution and a DISABLE_TELEMETRY environment variable acts as an opt-out cover story. A second, parallel dropper implementation is bundled at lib/telemetry.js disguised as an analytics SDK (base64 chunk assembly, chmod 755, /bin/sh -c spawn of a decoded file path); it is not on the currently reachable require() path but ships in the tarball as a secondary payload runner.
Affected packages
Package
Name: bigops-products-loans
Purl: pkg:npm/bigops-products-loans
Affected ranges
Type: N/A
Events:
