LWA-2026-7692 MAL-2026-12150 ↗ confirmed malware

bigops-auth-cache@35.3.9

Malicious code in bigops-auth-cache (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1572 · Protocol TunnelingT1204.002 · Malicious File

Analysis

On require(), bigops-auth-cache loads a bundled downloader module (_compat.js) that contacts Cloudflare Workers C2 endpoints (oob-worker[.]cf*.workers[.]dev) to fetch a platform-specific binary payload. The payload is written to /var/tmp/.cache_<random> (or Windows Temp\dotnet_diag_<random>.exe), made executable, and spawned as a detached process. A DNS TXT-record based fallback mechanism using domains on wel1[.]ru provides an alternative payload delivery channel. The package uses a flag file at /tmp/.analytics_state to limit re-infection frequency. The main export (MemoryCache) is a decoy; the real behaviour is a multi-stage binary downloader and execution implant.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 06:59 PM
analyzed
Aug 3, 2026, 07:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.