Malicious code in bigops-notes (npm)
The npm package bigops-notes version 35.8.7 contains malicious code that downloads and executes attacker-controlled binaries on the host system during import. It fetches platform-specific executables from multiple runtime-assembled domains and writes them to hidden temporary paths before execution, enabling arbitrary code execution. This behavior is disguised with no-op logging and decoy files to evade detection.
AI Analysis
Technical Summary
The bigops-notes npm package (version 35.8.7) includes a malicious _bootstrap.js script that, upon require(), selects a platform-specific asset and downloads an opaque binary from one of four dynamically assembled *.workers.dev hostnames, with a DNS-TXT base64 fallback to *.dl.wel1.ru. The binary is saved to a hidden path under /var/tmp or %TEMP% with a decoy filename, permissions set to executable, and then spawned detached via shell commands. The package uses obfuscation techniques such as splitting hostnames into arrays, no-op stderr logging, and decoy comment files to disguise its malicious activity. This results in arbitrary code execution on the host machine whenever the package is imported.
Potential Impact
This malicious package allows an attacker to execute arbitrary code on any system that installs and imports bigops-notes version 35.8.7. The attacker-controlled binaries are fetched from mutable, non-publisher-controlled URLs, enabling full compromise of the host environment. There are no known exploits in the wild reported yet, but the potential impact is critical due to arbitrary code execution.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or importing bigops-notes version 35.8.7. Remove any existing installations of this version from your environment and consider scanning for presence of the package and any spawned binaries. Monitor official advisories for updates or patches.
Malicious code in bigops-notes (npm)
Description
The npm package bigops-notes version 35.8.7 contains malicious code that downloads and executes attacker-controlled binaries on the host system during import. It fetches platform-specific executables from multiple runtime-assembled domains and writes them to hidden temporary paths before execution, enabling arbitrary code execution. This behavior is disguised with no-op logging and decoy files to evade detection.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bigops-notes npm package (version 35.8.7) includes a malicious _bootstrap.js script that, upon require(), selects a platform-specific asset and downloads an opaque binary from one of four dynamically assembled *.workers.dev hostnames, with a DNS-TXT base64 fallback to *.dl.wel1.ru. The binary is saved to a hidden path under /var/tmp or %TEMP% with a decoy filename, permissions set to executable, and then spawned detached via shell commands. The package uses obfuscation techniques such as splitting hostnames into arrays, no-op stderr logging, and decoy comment files to disguise its malicious activity. This results in arbitrary code execution on the host machine whenever the package is imported.
Potential Impact
This malicious package allows an attacker to execute arbitrary code on any system that installs and imports bigops-notes version 35.8.7. The attacker-controlled binaries are fetched from mutable, non-publisher-controlled URLs, enabling full compromise of the host environment. There are no known exploits in the wild reported yet, but the potential impact is critical due to arbitrary code execution.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or importing bigops-notes version 35.8.7. Remove any existing installations of this version from your environment and consider scanning for presence of the package and any spawned binaries. Monitor official advisories for updates or patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13227
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738520bf8831d5394ef921
Added to database: 08/05/2026, 18:46:56 UTC
Last enriched: 08/05/2026, 22:46:54 UTC
Last updated: 08/05/2026, 22:46:54 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.