bigops-chat-transfer@35.3.6
Malicious code in bigops-chat-transfer (npm)
Analysis
bigops-chat-transfer@35.3.6 is a multi-platform binary dropper. On require(), _platform.js constructs C2 hostnames via string concatenation pointing to Cloudflare Workers infrastructure (oob-worker.cf1*-baf[.]workers[.]dev), downloads a platform-specific binary (Linux x64/arm64, macOS, Windows) via HTTPS, with a DNS TXT-record-based fallback delivery mechanism (domains: sdk[.]dl[.]wel1[.]ru, ext[.]dl[.]wel1[.]ru, pkg[.]dl[.]wel1[.]ru, net[.]dl[.]wel1[.]ru). The downloaded binary is written to /var/tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows) and executed as a detached, unref'd child process. A lock file at /tmp/.analytics_state prevents repeated downloads. The package also ships an 81KB decoy analytics SDK (lib/telemetry.js) to appear legitimate.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 06:59 PM
- analyzed
- Aug 3, 2026, 07:00 PM
Related advisories
- tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci@20.1.2
- twork-products-taiga2-products-timeline@20.6.1
- beaver-ui-actions-button@5.4.7
- fdd41@1.0.0
- axios-native@1.16.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
- theme-color-picker@2.0.28
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.