LWA-2026-7678 MAL-2026-12036 ↗ confirmed malware

bigops-chat-tmsg@35.8.5

Malicious code in bigops-chat-tmsg (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1082 · System Information Discovery

Analysis

When required, the package silently downloads and executes a platform-specific binary payload. It fingerprints the host (OS, architecture) to select the correct binary, then attempts HTTPS downloads from three Cloudflare Workers C2 endpoints (oob-worker[.]cf101-adf[.]workers[.]dev, oob-worker[.]cf102-baf[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev) with random rotation. If HTTPS fails, it falls back to DNS TXT-based chunked payload retrieval from domains including sd[.]k[.]dl[.]wel1[.]ru. The downloaded binary is written to /var/tmp/.cache_<hex> (Linux/macOS) or %TEMP%\dotnet_diag_<hex>.exe (Windows), made executable, and spawned as a detached background process with stdio discarded. The package has no repository, no meaningful documentation, and its name impersonates an internal module pattern.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 06:58 PM
analyzed
Aug 3, 2026, 07:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.