{"id":"MAL-2026-13221","summary":"Malicious code in bigops-legacy-telephony-panel (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (610b2084c8573d9a89262f1a4dcd8ff26acdcc0568f7fa29ac5a921a292e390a)\nOn require of this package, index.js loads _init.js which at module load fetches a platform-specific binary from hostnames reassembled at runtime from split string arrays (oob-worker.cf10-1-adf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev), with a fallback that reconstructs a base64 payload from numbered DNS TXT records under c.\u003cdomain\u003e/\u003cn\u003e.\u003cdomain\u003e resolving under *.dl.wel1.ru. The retrieved bytes are written to /var/tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003chex\u003e.exe on Windows (filename mimicking.NET diagnostics), chmodded to 0o755, and spawned detached via spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) or spawn('cmd',...). Destination hosts are anonymous workers.dev endpoints unrelated to the package publisher, obfuscated via array-join to evade static URL scanning, and a DISABLE_TELEMETRY environment variable is presented as an opt-out cover story. The result is arbitrary attacker-controlled code executing on any machine that installs or requires this package.\n","modified":"2026-08-05T16:49:58.728408857Z","published":"2026-08-05T15:38:35Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015777","import_time":"2026-08-05T16:13:44.171592248Z","modified_time":"2026-08-05T15:38:35Z","sha256":"610b2084c8573d9a89262f1a4dcd8ff26acdcc0568f7fa29ac5a921a292e390a","source":"amazon-inspector","versions":["35.5.7"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-legacy-telephony-panel/v/35.5.7"}],"affected":[{"package":{"name":"bigops-legacy-telephony-panel","ecosystem":"npm","purl":"pkg:npm/bigops-legacy-telephony-panel"},"versions":["35.5.7"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-legacy-telephony-panel/MAL-2026-13221.json","indicators":{"evidence_files":[{"sha256":"7567d44b4e7977bebc63450ac0dc840595d5058987511c559a4f6b853055463c","tlsh":"6ba1965a12a6b0184f70e7e0c61b4416f66bf6633681c6c4f79c55944fb312483b2efc","path":"_init.js"}],"package_integrity":[{"filename":"bigops-legacy-telephony-panel-35.5.7.tgz","hashes":{"sha1":"f99df669b063f8a322015cf034fd9f32066c068c","sha512_sri":"sha512-pGytTt71CKXW1pIj5UrWhIqXI2X0VHBongWMDOQC7PdKUzT3oJ9Uiv46yg7wL+va5FBbXb0gKyj0Eaj0CRNFZw=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}