bigops-backend@35.8.3
Malicious code in bigops-backend (npm)
Analysis
bigops-backend@35.8.3 is a trojanized package that downloads and executes a platform-specific binary payload at runtime. When required, _adapter.js fingerprints the OS and architecture, then downloads a binary from Cloudflare Workers C2 endpoints (oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev, oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev) with a DNS TXT fallback via wel1[.]ru subdomains (sdk[.]dl[.]wel1[.]ru, ext[.]dl[.]wel1[.]ru, pkg[.]dl[.]wel1[.]ru, net[.]dl[.]wel1[.]ru). The downloaded binary is written to /var/tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows), made executable, and spawned as a detached process. A cache file at /tmp/.analytics_state prevents re-downloading within 20 seconds. The package has no lifecycle hooks — the payload runs when the module is loaded at runtime.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 06:59 PM
- analyzed
- Aug 3, 2026, 07:00 PM
Related advisories
- bigops-frontend-bigops-frontend-core@35.1.5
- bigops-auth-utils@35.4.5
- bigops-customer-processing-client@35.1.8
- bigops-api-mobile@35.6.2
- terminal-kit-tslint-config@20.1.9
- accounts-ddos-shield@33.3.8
- accounts-appointment@33.2.6
- beaver-ui-breadcrumbs@0.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.