{"id":"MAL-2026-13243","summary":"Malicious code in bigops-products-mobile (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (265e87afdb04434bf53739963fd1c91ddb80c8ac957384377898c0aaf87cf826)\nOn require('bigops-products-mobile'), index.js loads _loader.js which selects a platform-specific binary path, fetches attacker-controlled bytes over HTTPS from obfuscated Cloudflare Workers hosts (oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev) reconstructed at runtime by joining fragmented string arrays, with a DNS-TXT chunked fallback under *.dl.wel1.ru. The bytes are written to a disguised path ('.cache_\u003chex\u003e' on POSIX, 'dotnet_diag_\u003chex\u003e.exe' on Windows to impersonate a Microsoft diagnostic tool), chmod 0755'd, and detach-spawned via /bin/sh -c or cmd.exe with stdio ignored and unref()'d. No hash or signature verification is performed, the package's declared purpose ('device integration') has no dependencies and no relation to this behavior, and a persistence stamp is written to '.analytics_state' with telemetry/analytics-styled comments and DISABLE_TELEMETRY/DO_NOT_TRACK env checks used as cover. lib/telemetry.js ships a second, structurally identical fetch-\u003ebase64-\u003echmod 755-\u003e/bin/sh spawn dropper implementation (not currently wired from index.js but present in the tarball). Installing and importing this package yields remote code execution on the installer's host under attacker control.\n","modified":"2026-08-05T16:50:09.276485132Z","published":"2026-08-05T15:35:00Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T15:35:00Z","sha256":"265e87afdb04434bf53739963fd1c91ddb80c8ac957384377898c0aaf87cf826","source":"amazon-inspector","versions":["35.6.8"],"id":"IN-MAL-2026-015754","import_time":"2026-08-05T16:13:40.724314282Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-products-mobile/v/35.6.8"}],"affected":[{"package":{"name":"bigops-products-mobile","ecosystem":"npm","purl":"pkg:npm/bigops-products-mobile"},"versions":["35.6.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-products-mobile/MAL-2026-13243.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"bigops-products-mobile-35.6.8.tgz","hashes":{"sha1":"d8f99c306ecee8b04d58fc76375d1fa7528dd6aa","sha512_sri":"sha512-Q4h66LTxHLxabX06WPu2CJQJD3JLujobVFyadAJuToP1NlnKduEzu3TkoTP8KKjgHUWuy9xBHeVa3yr9u4mYgw=="}}],"evidence_files":[{"path":"_loader.js","sha256":"778d82c74ab2eecb2133923cfb62c446c6d0266df9d477ecb7cfd76120bedbd4","tlsh":"3db1b89a16aa71184bb0a7e4c7175416f65af2633380c6d4f75ca9981fb313483b2efc"},{"tlsh":"cf835056566a142186b2b378df234107ff3685272642429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js","sha256":"d882fd8646cfdbd06df8c1fa3131de6b9d1b0b3a853ccd9dcdfbb6189faaf3a7"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}