{"id":"MAL-2026-12156","summary":"Malicious code in bigops-chat-transfer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1d8d11b7e8abee5caddc5c2f1765fa7f10d40c8cce0ef1cafed55fe31537be94)\nOn require() of bigops-chat-transfer, _platform.js reconstructs one of three Cloudflare workers.dev hostnames from split string fragments (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev), downloads a platform-specific native binary over HTTPS, and — if HTTPS fails — falls back to a DNS-TXT covert channel under *.dl.wel1.ru that reconstructs a base64-encoded binary from sequentially numbered TXT records. The downloaded bytes are written to /var/tmp/.cache_\u003cuid\u003e on Unix or %TEMP%/dotnet_diag_\u003cuid\u003e.exe on Windows, chmod 0755'd, and spawned detached via /bin/sh -c or cmd /c start. A.analytics_state lock file provides rate-limit persistence, and the naming (dotnet_diag, analytics_state) is a cover story masquerading as.NET diagnostics telemetry. Destination hosts are not the package publisher's infrastructure, the fetched executable is opaque and unverified, and execution is triggered by ordinary import of the module.\n","modified":"2026-08-05T10:05:56.386686095Z","published":"2026-08-05T08:46:28Z","database_specific":{"malicious-packages-origins":[{"sha256":"1d8d11b7e8abee5caddc5c2f1765fa7f10d40c8cce0ef1cafed55fe31537be94","source":"amazon-inspector","versions":["35.3.6"],"id":"IN-MAL-2026-014411","import_time":"2026-08-05T09:28:08.035506578Z","modified_time":"2026-08-05T08:46:28Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-chat-transfer/v/35.3.6"}],"affected":[{"package":{"name":"bigops-chat-transfer","ecosystem":"npm","purl":"pkg:npm/bigops-chat-transfer"},"versions":["35.3.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"fea1879e166a70194bb097e4c72b4816f65bf2633380d2d4fa5ca5941fb31248371efc","path":"_platform.js","sha256":"51f03e9e7970bf053a490f07d2764a15e55d853c7ed8d2384ec53b92fb27f306"}],"package_integrity":[{"filename":"bigops-chat-transfer-35.3.6.tgz","hashes":{"sha1":"797b8708f3536696d4584b78223087b1e389f1e1","sha512_sri":"sha512-U3oE+zz2lGVbEpxXGoyWuWGkPmg03JBMpjKR/3LB0lLWvgPSRaEI4D/bz6rXE2MwJiz6c468et4Pr4aUoekt4A=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-chat-transfer/MAL-2026-12156.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}