🛡️ MAL-2026-12161 — bigops-communication-client
Description
Malicious code in bigops-communication-client (npm)
Source: amazon-inspector
On require() of the package, index.js loads _platform.js which invokes init() at module top level. init() downloads an opaque binary from Cloudflare Workers subdomains (oob-worker.cf102-baf.workers.dev, cf100-416, cf103-070, cf99-9b3.workers.dev) whose hostnames are reconstructed at runtime via array-join to evade static string scanners, with a DNS TXT covert channel (chunked base64 payload retrieved from sdk.dl.wel1.ru) as fallback. The fetched bytes are written to /tmp or %TEMP% under names impersonating.NET diagnostic tools (dotnet_diag_<tag>.exe,.cache_<tag>), chmod 0755 on Unix, then spawned detached via /bin/sh -c or cmd.exe start /b with stdio ignored. Anti-analysis logic aborts execution if DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK are set and stamps /tmp/.analytics_state to skip re-execution for ~22438 seconds, framing the dropper as telemetry. There is no legitimate purpose for a require()-time fetch-and-execute of an unpinned, unverified binary from anonymous Workers hosts with runtime host reconstruction and a DNS-TXT payload channel.
Affected software
MAL-2026-12161 is recorded against 1 package.
- bigops-communication-client
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| bigops-communication-client | — | — |
References
Free Vulnerability Check
Is your site affected by MAL-2026-12161?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12161 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.