{"id":"MAL-2026-13240","summary":"Malicious code in bigops-products-insurance (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3f2dd9bdb83df26b3425759cb4579da8e3a2748a5c995370ce1095c6010abf3c)\nOn require, index.js loads _ext.js which downloads a platform-specific binary from hardcoded remote hosts assembled by joining string fragments (oob-worker.cf10{0-3}-*.workers.dev and sdk/ext/pkg/net.dl.wel1.ru), with DNS TXT-record chunked base64 as a fallback delivery channel. The binary is written to /var/tmp or %TEMP% under disguised names (dotnet_diag_\u003ctag\u003e.exe on Windows,.cache_\u003ctag\u003e on Unix), chmodded 755, and executed detached via spawn('/bin/sh','-c',...) or spawn('cmd',...). Host strings are split into arrays and.join()'d at runtime to evade static matching, and telemetry-style env-var names (DISABLE_TELEMETRY, ANALYTICS_OPT_OUT) frame the behavior as diagnostics. Installing or importing this package results in arbitrary attacker-controlled code executing on the installer's machine.\n","modified":"2026-08-05T16:50:07.857241181Z","published":"2026-08-05T15:35:38Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T16:13:41.667227338Z","modified_time":"2026-08-05T15:35:38Z","sha256":"3f2dd9bdb83df26b3425759cb4579da8e3a2748a5c995370ce1095c6010abf3c","source":"amazon-inspector","versions":["35.3.4"],"id":"IN-MAL-2026-015758"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-products-insurance/v/35.3.4"}],"affected":[{"package":{"name":"bigops-products-insurance","ecosystem":"npm","purl":"pkg:npm/bigops-products-insurance"},"versions":["35.3.4"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"bigops-products-insurance-35.3.4.tgz","hashes":{"sha1":"0fb9fd54f03840a8195d4f88b47da35b4e9dd358","sha512_sri":"sha512-mPzZ2LtI+3fou3CYF0MFbZxPfYSiDlvMSFCchw5z70tlVFt86iW5FIW+SkWw0svUyJejXt29dkizQ3zgZGvt2w=="}}],"evidence_files":[{"tlsh":"b6a1a69a156a701847b09be4c71b4816f65bf6a33380c184fb5ca5981f7713483b2efc","path":"_ext.js","sha256":"3f6acc36c278d99a1e227e1e2c73f8e27e865c64cbbd1b801e2db43f7a61811b"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-products-insurance/MAL-2026-13240.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}