Malicious code in bigops-api-mobile (npm)
The npm package bigops-api-mobile version 35.6.2 contains malicious code that downloads and executes arbitrary code from obfuscated Cloudflare Workers endpoints without integrity verification. This results in full host compromise upon installation or execution of the package. The malicious payload uses multiple fallback mechanisms including a DNS-TXT covert channel to ensure execution. Removal of the package does not guarantee full remediation as the system may already be fully compromised.
AI Analysis
Technical Summary
The bigops-api-mobile npm package version 35.6.2 includes a malicious payload that, upon require(), loads a runtime script which dynamically reconstructs obfuscated Cloudflare Workers subdomains and downloads executable code over HTTPS without hash or signature verification. The downloaded code is saved to disguised temporary files with executable permissions and launched detached via shell commands, enabling full host code execution controlled by the attacker. A DNS-TXT based covert channel fallback reassembles a base64 payload from indexed subdomains if HTTPS delivery fails. Secondary activation paths exist via telemetry.js, which contains similar dropper primitives. The obfuscation techniques defeat static detection, and the lack of publisher verification means the host is fully compromised once the package is installed or run.
Potential Impact
Any system with this package installed or running is considered fully compromised, allowing attackers full control over the host. All secrets and keys stored on the compromised system should be considered exposed and must be rotated from a secure environment. Removal of the package alone does not guarantee removal of all malicious artifacts or backdoors introduced by the payload.
Mitigation Recommendations
Immediate removal of the bigops-api-mobile package version 35.6.2 is recommended. All secrets and credentials stored on the affected system should be rotated from a different, trusted machine. Due to the full host compromise risk, a full system reinstallation or forensic analysis is advised to ensure complete remediation. No official patch or fix is available; patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in bigops-api-mobile (npm)
Description
The npm package bigops-api-mobile version 35.6.2 contains malicious code that downloads and executes arbitrary code from obfuscated Cloudflare Workers endpoints without integrity verification. This results in full host compromise upon installation or execution of the package. The malicious payload uses multiple fallback mechanisms including a DNS-TXT covert channel to ensure execution. Removal of the package does not guarantee full remediation as the system may already be fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bigops-api-mobile npm package version 35.6.2 includes a malicious payload that, upon require(), loads a runtime script which dynamically reconstructs obfuscated Cloudflare Workers subdomains and downloads executable code over HTTPS without hash or signature verification. The downloaded code is saved to disguised temporary files with executable permissions and launched detached via shell commands, enabling full host code execution controlled by the attacker. A DNS-TXT based covert channel fallback reassembles a base64 payload from indexed subdomains if HTTPS delivery fails. Secondary activation paths exist via telemetry.js, which contains similar dropper primitives. The obfuscation techniques defeat static detection, and the lack of publisher verification means the host is fully compromised once the package is installed or run.
Potential Impact
Any system with this package installed or running is considered fully compromised, allowing attackers full control over the host. All secrets and keys stored on the compromised system should be considered exposed and must be rotated from a secure environment. Removal of the package alone does not guarantee removal of all malicious artifacts or backdoors introduced by the payload.
Defensive Guidance
Immediate removal of the bigops-api-mobile package version 35.6.2 is recommended. All secrets and credentials stored on the affected system should be rotated from a different, trusted machine. Due to the full host compromise risk, a full system reinstallation or forensic analysis is advised to ensure complete remediation. No official patch or fix is available; patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12148
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-342j-gf24-vx6v"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a74cfafbf8831d5391b2403
Added to database: 08/06/2026, 18:17:19 UTC
Last enriched: 08/06/2026, 19:37:02 UTC
Last updated: 08/06/2026, 19:37:02 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.