MAL-2026-12036
Malicious code in bigops-chat-tmsg (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d69edae547a80f52eb90bff45074d0b7837e7c9c248c6e203ac1cb31ba2b6ae4) On require() of bigops-chat-tmsg, index.js silently loads _runtime.js (via a swallowed try/require appended after an empty stub class exposing init/version/configure). _runtime.js selects a platform-specific asset and downloads a binary from one of three string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, cf102-baf.workers.dev, cf103-070.workers.dev), writes it to /var/tmp or %TEMP% under a disguised name (.cache_<hex> on Unix, dotnet_diag_<hex>.exe on Windows impersonating a Microsoft diagnostic tool), chmods 0755, and spawns it detached via /bin/sh -c or cmd. If HTTPS fetches fail, the code falls back to a covert DNS-TXT channel at split-string-reconstructed domains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru): it resolves TXT records for a chunk count on c.<domain> and reassembles a base64-encoded executable from numbered subdomain TXT responses. The package name/description advertise a chat/messaging library, but the entire real behavior is the dropper; the exported API is a do-nothing stub used as cover.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for bigops-chat-tmsg (npm). Pin to a known-safe version or switch to an alternative.