LWA-2026-7670 MAL-2026-12156 ↗ confirmed malware

bigops-chat-transfer@35.3.6

Malicious code in bigops-chat-transfer (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.004 · DNST1204.002 · Malicious FileT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or Location

Analysis

bigops-chat-transfer@35.3.6 is a multi-platform binary dropper. On require(), _platform.js constructs C2 hostnames via string concatenation pointing to Cloudflare Workers infrastructure (oob-worker.cf1*-baf[.]workers[.]dev), downloads a platform-specific binary (Linux x64/arm64, macOS, Windows) via HTTPS, with a DNS TXT-record-based fallback delivery mechanism (domains: sdk[.]dl[.]wel1[.]ru, ext[.]dl[.]wel1[.]ru, pkg[.]dl[.]wel1[.]ru, net[.]dl[.]wel1[.]ru). The downloaded binary is written to /var/tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows) and executed as a detached, unref'd child process. A lock file at /tmp/.analytics_state prevents repeated downloads. The package also ships an 81KB decoy analytics SDK (lib/telemetry.js) to appear legitimate.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 06:59 PM
analyzed
Aug 3, 2026, 07:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.