bigops-data-storage@35.7.1
Malicious code in bigops-data-storage (npm)
Analysis
The package loads a bundled module (_compat.js) on require that downloads a platform-specific binary from Cloudflare Workers C2 infrastructure and executes it as a detached process. The C2 hosts are oob-worker[.]cf101-a[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, and oob-worker[.]cf100-416[.]workers[.]dev. A DNS-based fallback mechanism uses domains under wel1[.]ru. The downloaded binary is saved to /var/tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows) and spawned detached. The package has no repository, no README content beyond boilerplate, and no documented purpose matching its name.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 06:58 PM
- analyzed
- Aug 3, 2026, 07:03 PM
Related advisories
- bigops-auth@35.8.6
- bigops-file-storage@35.1.2
- bigops-awesome-viewer@35.1.4
- bigops-chat-transfer@35.3.6
- bigops-frontend-bigops-frontend-core@35.1.5
- bigops-auth-cache@35.3.9
- bigops-communication-client@35.8.8
- bigops-auth-utils@35.4.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.