LWA-2026-7693 MAL-2026-12061 ↗ confirmed malware

bigops-eslint@35.9.5

Malicious code in bigops-eslint (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

bigops-eslint@35.9.5 is a trojanized package masquerading as a code style enforcer. On require(), it downloads a platform-specific native binary from Cloudflare Workers subdomains (oob-worker[.]cf100-416[.]workers[.]dev, oob-worker[.]cf103-070[.]workers[.]dev, oob-worker[.]cf101-adf[.]workers[.]dev) via HTTPS, with a DNS TXT chunked fallback from wel1[.]ru domains (sdk[.]dl[.]wel1[.]ru, ext[.]dl[.]wel1[.]ru, pkg[.]dl[.]wel1[.]ru, net[.]dl[.]wel1[.]ru). The downloaded binary is written to /var/tmp/.cache_<hex> (Linux/macOS) or %TEMP%\dotnet_diag_<hex>.exe (Windows) and executed as a detached background process. The package also collects system information (hostname, platform, CPU count, memory, CI environment) and sends it to the same C2 infrastructure. No repository or documentation is provided.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 06:59 PM
analyzed
Aug 3, 2026, 07:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.