{"id":"MAL-2026-13245","summary":"Malicious code in bigops-products-timeline (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f972f857c08272cf44608802d91460fade21f3db145ac925f4d6bb7f00cdf9f8)\nOn require(), index.js loads _vendor.js which immediately runs a main() routine that downloads a platform-specific binary from Cloudflare Workers endpoints reconstructed at runtime by joining split character arrays (e.g. ['oob-worke','r.cf100-416.workers.d','ev'].join('')), with a DNS TXT fallback resolving *.dl.wel1.ru (sdk./ext./pkg./net.dl.wel1.ru). The fetched bytes are written to /tmp or %TEMP% under disguised names such as.cache_\u003chex\u003e or dotnet_diag_\u003chex\u003e.exe, chmod 0755, and executed detached via spawn('/bin/sh', ['-c', fp + ' &']) or spawn('cmd',...). The package advertises itself as a 'shared timeline library' — none of the fetch-and-execute behavior is required by that purpose. String-split hostname reconstruction is used to defeat static URL/domain scanners.\n","modified":"2026-08-05T16:50:10.554828733Z","published":"2026-08-05T15:35:29Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015757","import_time":"2026-08-05T16:13:41.375734902Z","modified_time":"2026-08-05T15:35:29Z","sha256":"f972f857c08272cf44608802d91460fade21f3db145ac925f4d6bb7f00cdf9f8","source":"amazon-inspector","versions":["35.8.9"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-products-timeline/v/35.8.9"}],"affected":[{"package":{"name":"bigops-products-timeline","ecosystem":"npm","purl":"pkg:npm/bigops-products-timeline"},"versions":["35.8.9"],"database_specific":{"indicators":{"evidence_files":[{"path":"_vendor.js","sha256":"03aa97bb87fca1d6da53fb69bc6ca261cf05281c6a8b97421200d1c3300cb4f4","tlsh":"33a1b79a16aa70194bb09be4c6174415f65be76333c0c188fb5ca9885fb3124c3b2efc"}],"package_integrity":[{"filename":"bigops-products-timeline-35.8.9.tgz","hashes":{"sha1":"556c8e5ce958ceaf00be33f9d0640c9d5ec71b50","sha512_sri":"sha512-J2I/j6DFkgJ37m8+Lxnt/w6k2VY6gVgYxOERpr1xeLXrcpO6RwSZOqQvAprdJBop5E2KcD0xblOYs0l/033TGQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-products-timeline/MAL-2026-13245.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}