{"id":"MAL-2026-12153","summary":"Malicious code in bigops-awesome-viewer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f1204820931e9021a079d3347320d6c127f68297ee6b0223b37967f6c2601f78)\nindex.js unconditionally require()s./_loader on module load. _loader.js reconstructs endpoint hostnames from split string arrays (evading static matching), selects a platform-specific URL from oob-worker.cf101-adf.workers.dev / oob-worker.cf102-baf.workers.dev / oob-worker.cf103-070.workers.dev, and falls back to a chunked base64 DNS-TXT channel over sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru when HTTPS fails. The fetched opaque binary is written to /var/tmp/.cache_\u003chex\u003e on Unix (or %TEMP%/dotnet_diag_\u003chex\u003e.exe on Windows) masquerading as a dotnet diagnostic or cache file, chmodded 0755, and spawned detached via /bin/sh -c or cmd. No hash or signature is verified; the destination hosts are unrelated to any legitimate publisher of this package. A marker file /tmp/.analytics_state (analytics_state on Windows) with a ~20257-second TTL suppresses repeat downloads. lib/telemetry.js ships a second copy of the drop-and-exec primitives (Buffer.from(chunks,'base64'), fs['chmod'+'Sync'](path, 0o755), cp.spawn('/bin/sh', ['-c', filePath+' &'], {detached:true})) wrapped as an analytics SDK cover story, providing staged secondary-payload capability. Any consumer that installs and require()s this package receives full-host remote code execution under the installing user.\n","modified":"2026-08-05T10:05:55.135422392Z","published":"2026-08-05T08:45:56Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014407","import_time":"2026-08-05T09:28:07.48609075Z","modified_time":"2026-08-05T08:45:56Z","sha256":"f1204820931e9021a079d3347320d6c127f68297ee6b0223b37967f6c2601f78","source":"amazon-inspector","versions":["35.1.4"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-awesome-viewer/v/35.1.4"}],"affected":[{"package":{"name":"bigops-awesome-viewer","ecosystem":"npm","purl":"pkg:npm/bigops-awesome-viewer"},"versions":["35.1.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-awesome-viewer/MAL-2026-12153.json","indicators":{"package_integrity":[{"filename":"bigops-awesome-viewer-35.1.4.tgz","hashes":{"sha1":"cbf33529d210be9eea5d1076f6b18a111218a751","sha512_sri":"sha512-B14bBX5LYXNHIKU4ifw5rKpVZRGyWzsTBkNfisQYDjz8VhRG1qECayH3Yn6+1FvC0E6opyT0uqWsFn+O6yTGYg=="}}],"evidence_files":[{"sha256":"ad195e2f1c008fb8e88b0d2e4bd45d4405b311d66af778ec9f687aa4b2ccd02b","tlsh":"48a1989a1166b01c8bb0d7e0c7179819fa5bfa6332c18184f75c55945f7352483b1efc","path":"_loader.js"},{"tlsh":"55835055566a142186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"edfca575105254a3d828b71f29d0d2d54fda17f766c171afcd29914e4ac697f5"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}