{"id":"MAL-2026-13226","summary":"Malicious code in bigops-nitro-events-table (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6d222994e1816e63b4047f5396bbfda8d6d2ccd6bbc840da4872aa026f879525)\nThe package's index.js requires./_shim on load. _shim.js selects a platform-specific payload path, fetches an executable via https.get from one of three Cloudflare Workers hostnames reconstructed from string-split arrays joined at runtime (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS-TXT base64 fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru. The downloaded binary is written to /var/tmp/.cache_\u003crand\u003e on Unix or %TEMP%/dotnet_diag_\u003crand\u003e.exe on Windows, chmodded 0755, and spawned detached via /bin/sh -c '\u003cpath\u003e &' or cmd /c start. Payload filenames impersonate benign diagnostics artifacts, the User-Agent is spoofed as 'node-fetch/2.6', a.analytics_state lock file is used, and the payload is skipped when DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env vars are set — an evasion to blend in as telemetry and avoid privacy-conscious hosts. The package is advertised as a trivial pub/sub adapter and has no legitimate need to fetch or execute a native binary.\n","modified":"2026-08-05T16:50:01.228945602Z","published":"2026-08-05T15:37:50Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T16:13:43.516089014Z","modified_time":"2026-08-05T15:37:50Z","sha256":"6d222994e1816e63b4047f5396bbfda8d6d2ccd6bbc840da4872aa026f879525","source":"amazon-inspector","versions":["35.4.2"],"id":"IN-MAL-2026-015772"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-nitro-events-table/v/35.4.2"}],"affected":[{"package":{"name":"bigops-nitro-events-table","ecosystem":"npm","purl":"pkg:npm/bigops-nitro-events-table"},"versions":["35.4.2"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-nS8pZRZcgWKAgtSzYFKUNlDQ/agflkyrFbToDPep06xvpvgqfwMvaTrCvGU7jYSuTLTm7Vv/0d/o5jF42lpKPg==","sha1":"98cb5fcf5aa434f2005c56fccd050c851da17fd4"},"filename":"bigops-nitro-events-table-35.4.2.tgz"}],"evidence_files":[{"tlsh":"52a1959a1266301d8bb0ebe08b175419f65af6633380c294fb5c69d85fb212483b2dfc","path":"_shim.js","sha256":"d81068ad8fcad23f757cfd2ec5a005d26ac8629a5eadacd749ef77873c7abb61"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-nitro-events-table/MAL-2026-13226.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}