bigops-eslint@35.9.5
Malicious code in bigops-eslint (npm)
Analysis
bigops-eslint@35.9.5 is a trojanized package masquerading as a code style enforcer. On require(), it downloads a platform-specific native binary from Cloudflare Workers subdomains (oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev) via HTTPS, with a DNS TXT chunked fallback from wel1[.]ru domains (sdk[.]dl[.]wel1[.]ru, ext[.]dl[.]wel1[.]ru, pkg[.]dl[.]wel1[.]ru, net[.]dl[.]wel1[.]ru). The downloaded binary is written to /var/tmp/.cache_<hex> (Linux/macOS) or %TEMP%\dotnet_diag_<hex>.exe (Windows) and executed as a detached background process. The package also collects system information (hostname, platform, CPU count, memory, CI environment) and sends it to the same C2 infrastructure. No repository or documentation is provided.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 06:59 PM
- analyzed
- Aug 3, 2026, 07:00 PM
Related advisories
- bigops-backend@35.8.3
- bigops-frontend-bigops-frontend-core@35.1.5
- bigops-auth-utils@35.4.5
- bigops-customer-processing-client@35.1.8
- bigops-api-mobile@35.6.2
- terminal-kit-tslint-config@20.1.9
- accounts-ddos-shield@33.3.8
- accounts-appointment@33.2.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.