bigops-timeline@35.4.9
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC
OSV ID
MAL-2026-12844
Ecosystem
npm
Summary
On require('bigops-timeline'), index.js loads _helpers.js which runs immediately: it selects a platform-specific payload path, downloads a binary from a rotating list of Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev), with a DNS TXT chunked base64 fallback under sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru, writes the fetched bytes to /var/tmp or %TEMP% under disguised names (e.g., dotnet_diag_*.exe,.cache_*), chmods 0755, and spawns the file detached via /bin/sh -c or cmd.exe start /b. Destination hosts are assembled from split string fragments (e.g., ['oob-worker.cf99-9b3.workers.de','v'].join('')) to defeat static scanners, and no hash or signature verification is performed on the downloaded payload. The purpose-agnostic name and the anonymous, rotating, obfuscated infrastructure identify this as a dropper rather than a legitimate native-binary loader.
Source: amazon-inspector (d39f8f76c66cd667590e9159602b8c4ce9172a84fdf859f0b11fb862efb068b2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.