bigops-auth-cache@35.3.9
Malicious code in bigops-auth-cache (npm)
Analysis
On require(), bigops-auth-cache loads a bundled downloader module (_compat.js) that contacts Cloudflare Workers C2 endpoints (oob-worker[.]cf*.workers[.]dev) to fetch a platform-specific binary payload. The payload is written to /var/tmp/.cache_<random> (or Windows Temp\dotnet_diag_<random>.exe), made executable, and spawned as a detached process. A DNS TXT-record based fallback mechanism using domains on wel1[.]ru provides an alternative payload delivery channel. The package uses a flag file at /tmp/.analytics_state to limit re-infection frequency. The main export (MemoryCache) is a decoy; the real behaviour is a multi-stage binary downloader and execution implant.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 06:59 PM
- analyzed
- Aug 3, 2026, 07:00 PM
Related advisories
- bigops-cobrowsing@35.4.9
- entropyeasybots@2.0.2
- a.poltoradnev-package-b@33.9.1
- pfp-forms-independent-sme-glossary-anchor@20.4.4
- twork-data-services-ng14-aggregator-api-v2-data-view-user-b2b-create-deal-mf-config@20.6.1
- form-bnpl-dolyame-component-object@20.8.9
- tinkoff-pfp-atom-desktop-carousel@20.8.8
- streak-metrics-math@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.