Logo
npm

bigops-utils@35.4.8

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-12853

Ecosystem

npm

Summary

Loading the package's main entry point auto-invokes _helpers.js init(), which downloads an OS-specific binary from obfuscated Cloudflare Workers subdomains (hostnames assembled at runtime from split-string arrays such as _MIRRORS=['oob-worker.cf102-baf.w','orke','rs.','de','v'].join('')) with a DNS-TXT chunked fallback that reassembles base64 chunks from TXT records under *.dl.wel1.ru. The fetched bytes are written to /tmp or %TEMP% under deceptive names ('.cache_<rand>', 'dotnet_diag_<rand>.exe'), chmod'd 0755, and detached-spawned via spawn('/bin/sh', ['-c', fp+' &'], {detached:true}) or cmd.exe /c start /b. No hash or signature verification is performed and the destinations are not tied to any advertised publisher. Sibling lib/telemetry.js uses dynamic API construction (require('child_'+'process'), fs['chmod'+'Sync']) to further evade static analysis. The behavior is framed as 'analytics/telemetry' but is an import-time remote-code dropper.

Source: amazon-inspector (36dcb322eace39209bb0092ab7ea7c658481887a48eff948f116bfb7909ec131)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.