{"id":"MAL-2026-12151","summary":"Malicious code in bigops-auth-interceptor (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (018aa5e99b7e6aa9f438b51ee00164801a2eb1c52e78ad123d0c490dced4b67c)\nOn require() of bigops-auth-interceptor@35.7.2, index.js loads _vendor.js which selects a platform-specific binary URL, downloads bytes over HTTPS from one of four string-concatenation-obfuscated Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev), writes them to a temp path under a disguised name (dotnet_diag_\u003chex\u003e.exe on Windows,.cache_\u003chex\u003e on Linux), chmods 0755, and spawns the file detached via /bin/sh -c or cmd.exe. A DNS TXT-record fallback channel (c.\u003cdomain\u003e returns a chunk count, then i.\u003cdomain\u003e TXT records are concatenated and base64-decoded into the payload) is implemented against sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, providing covert payload retrieval when HTTPS is blocked. A run-once marker file (.analytics_state) prevents repeated execution. Destination hosts are unrelated to any legitimate publisher of the package's stated purpose; the fetched bytes are unpinned, unsigned, and platform-selected.\n","modified":"2026-08-05T10:05:53.867142439Z","published":"2026-08-05T08:45:31Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T08:45:31Z","sha256":"018aa5e99b7e6aa9f438b51ee00164801a2eb1c52e78ad123d0c490dced4b67c","source":"amazon-inspector","versions":["35.7.2"],"id":"IN-MAL-2026-014404","import_time":"2026-08-05T09:28:07.058275288Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-auth-interceptor/v/35.7.2"}],"affected":[{"package":{"name":"bigops-auth-interceptor","ecosystem":"npm","purl":"pkg:npm/bigops-auth-interceptor"},"versions":["35.7.2"],"database_specific":{"indicators":{"package_integrity":[{"filename":"bigops-auth-interceptor-35.7.2.tgz","hashes":{"sha1":"d6158fce1d3fb7ef31b4c18e746e1477f3ef701b","sha512_sri":"sha512-p7oyDy3wU7hFk3JRf3nkDFBlW/CywfBxtLuck33yv4QmtGukvVw/t4enniwOqctR3s9wwjU+BQAxtoh2r5VTrQ=="}}],"evidence_files":[{"path":"_vendor.js","sha256":"7d2e372f29a368fcf9fdf2007df55b3fe46a78c41109260433d43d91ad2d3655","tlsh":"22a1865a156a70194bb0dbe48b1b541af65bf6533380c2d4fb6ca5981f731148372dfc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-auth-interceptor/MAL-2026-12151.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}