VDB
EN

MAL-2026-12038

Malicious code in bigops-customer (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (59163c2270e2c84a960164463cb31d73a8db2e80e484d7d58d44ed2d32d36f0a) The package's main entry requires `./_ext`, which on load downloads a platform-specific binary from hardcoded Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, cf99-9b3.workers.dev, cf102-baf.workers.dev), assembled at runtime from split string fragments to evade static analysis. The fetched bytes are written to /tmp or %TEMP% under a disguised name (`.cache_<hex>` on Unix, `dotnet_diag_<hex>.exe` on Windows), chmod 0755'd, and spawned detached via `/bin/sh` or `cmd.exe`. No hash or signature verification. A DNS TXT-record fallback channel (`c.<domain>` chunk count plus numbered subdomains, base64-decoded and joined) retrieves the payload when HTTPS fails. Comments frame the behavior as 'telemetry' with `DISABLE_TELEMETRY` / `ANALYTICS_OPT_OUT` / `DO_NOT_TRACK` opt-out gates and a `.analytics_state` re-run cooldown marker; the package description ('Bigops customer abstraction layer') is generic and unrelated to the actual code. Destinations are anonymous serverless hosts unrelated to any publisher identity; the fetched code is opaque and runs with the installer's privileges as a consequence of `require('bigops-customer')`.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / bigops-customer

No fixed version published yet for bigops-customer (npm). Pin to a known-safe version or switch to an alternative.

참고