LWA-2026-7677 MAL-2026-12163 ↗ confirmed malware

bigops-data-storage@35.7.1

Malicious code in bigops-data-storage (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1204.002 · Malicious File

Analysis

The package loads a bundled module (_compat.js) on require that downloads a platform-specific binary from Cloudflare Workers C2 infrastructure and executes it as a detached process. The C2 hosts are oob-worker[.]cf101-a[.]workers[.]dev, oob-worker[.]cf99-9b3[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, and oob-worker[.]cf100-416[.]workers[.]dev. A DNS-based fallback mechanism uses domains under wel1[.]ru. The downloaded binary is saved to /var/tmp/.cache_<random> (Linux/macOS) or %TEMP%\dotnet_diag_<random>.exe (Windows) and spawned detached. The package has no repository, no README content beyond boilerplate, and no documented purpose matching its name.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 06:58 PM
analyzed
Aug 3, 2026, 07:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.