{"id":"MAL-2026-12166","summary":"Malicious code in bigops-figma-to-html (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c9d43dbcd2d43f28af8266fac2d7e08a782dfbaaac1d02375438095a8001b24e)\nOn require, index.js unconditionally loads _bootstrap.js, which selects a platform-specific endpoint, fetches an opaque binary from author-controlled Cloudflare Workers subdomains (oob-worker.cf*.workers.dev) with a DNS-TXT chunked fallback over *.dl.wel1.ru (sdk/ext/pkg/net.dl.wel1.ru), writes it to /var/tmp/.cache_\u003chex\u003e on POSIX or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows, chmods 0755, and spawns it detached and unref'd via /bin/sh -c or cmd. Destination hostnames are constructed at runtime by joining split-string fragments (e.g. [\"oob-wo\",\"rker.cf103-070.worke\",\"rs.de\",\"v\"].join(\"\")) to hide them from static scanners. The DNS-TXT fallback retrieves a chunk count from c.\u003cdomain\u003e and reassembles base64 chunks from N.\u003cdomain\u003e, providing a covert delivery channel that bypasses HTTPS egress filtering. No hash or signature verification is performed; filenames impersonate dotnet diagnostics artifacts; opt-out is only via undocumented environment variables.\n","modified":"2026-08-05T10:06:01.809151869Z","published":"2026-08-05T08:47:13Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.5.5"],"id":"IN-MAL-2026-014416","import_time":"2026-08-05T09:28:08.755427646Z","modified_time":"2026-08-05T08:47:13Z","sha256":"c9d43dbcd2d43f28af8266fac2d7e08a782dfbaaac1d02375438095a8001b24e"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-figma-to-html/v/35.5.5"}],"affected":[{"package":{"name":"bigops-figma-to-html","ecosystem":"npm","purl":"pkg:npm/bigops-figma-to-html"},"versions":["35.5.5"],"database_specific":{"indicators":{"package_integrity":[{"filename":"bigops-figma-to-html-35.5.5.tgz","hashes":{"sha512_sri":"sha512-EoYsMxQJ8km02r5rJRakz30jgyfQ+KgGfIljSetWh+X8Vx3389XOdsYvRbYsxtjfu1RM5DbrcvVdp6Eoounc5A==","sha1":"cab47fa892437c4cc042c7920828ad90ba734dff"}}],"evidence_files":[{"path":"_bootstrap.js","sha256":"a3a85a7652f9fc27ad41f2eab3db23a0241f35791fbea267c296f4d524b91d6a","tlsh":"82a1969a16a670198f70d7e487174416f66be6633280c2d4f75ca9941fb613483b2efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-figma-to-html/MAL-2026-12166.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}