Malicious code in bigops-products-timeline (npm)
The bigops-products-timeline npm package version 35.8.9 contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints and fallback domains. This behavior is unrelated to the package's advertised purpose as a shared timeline library. The malicious code uses string-splitting techniques to evade static URL and domain scanners, writes the downloaded binaries to temporary directories with disguised names, sets executable permissions, and runs them detached from the main process.
AI Analysis
Technical Summary
The bigops-products-timeline package (version 35.8.9) includes a malicious payload triggered on require(). It loads a _vendor.js script that downloads a platform-specific binary from dynamically reconstructed Cloudflare Workers URLs, with a DNS TXT fallback resolving to *.dl.wel1.ru domains. The binary is saved under disguised filenames in temporary directories, made executable, and executed detached via shell commands. The obfuscation techniques used aim to evade static detection mechanisms. This fetch-and-execute behavior is not required for the package's stated functionality, indicating intentional malicious activity.
Potential Impact
The malicious code enables arbitrary code execution on the host system by downloading and running external binaries without user consent. This can lead to system compromise, data theft, persistence, or further malware deployment. Because the binaries are executed detached, detection and containment may be more difficult. The obfuscation of download URLs complicates detection by static analysis tools.
Mitigation Recommendations
No official patch or remediation guidance is provided. Users should immediately remove and avoid using version 35.8.9 of the bigops-products-timeline package. Audit systems for any signs of execution of unknown binaries from temporary directories. Consider blocking network requests to the identified domains and Cloudflare Workers endpoints. Monitor for suspicious processes spawned from temporary files named like .cache_<hex> or dotnet_diag_<hex>.exe. Replace the package with a trusted alternative or a clean version if available.
Malicious code in bigops-products-timeline (npm)
Description
The bigops-products-timeline npm package version 35.8.9 contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints and fallback domains. This behavior is unrelated to the package's advertised purpose as a shared timeline library. The malicious code uses string-splitting techniques to evade static URL and domain scanners, writes the downloaded binaries to temporary directories with disguised names, sets executable permissions, and runs them detached from the main process.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bigops-products-timeline package (version 35.8.9) includes a malicious payload triggered on require(). It loads a _vendor.js script that downloads a platform-specific binary from dynamically reconstructed Cloudflare Workers URLs, with a DNS TXT fallback resolving to *.dl.wel1.ru domains. The binary is saved under disguised filenames in temporary directories, made executable, and executed detached via shell commands. The obfuscation techniques used aim to evade static detection mechanisms. This fetch-and-execute behavior is not required for the package's stated functionality, indicating intentional malicious activity.
Potential Impact
The malicious code enables arbitrary code execution on the host system by downloading and running external binaries without user consent. This can lead to system compromise, data theft, persistence, or further malware deployment. Because the binaries are executed detached, detection and containment may be more difficult. The obfuscation of download URLs complicates detection by static analysis tools.
Mitigation Recommendations
No official patch or remediation guidance is provided. Users should immediately remove and avoid using version 35.8.9 of the bigops-products-timeline package. Audit systems for any signs of execution of unknown binaries from temporary directories. Consider blocking network requests to the identified domains and Cloudflare Workers endpoints. Monitor for suspicious processes spawned from temporary files named like .cache_<hex> or dotnet_diag_<hex>.exe. Replace the package with a trusted alternative or a clean version if available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13245
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738521bf8831d5394ef977
Added to database: 08/05/2026, 18:46:57 UTC
Last enriched: 08/05/2026, 22:32:14 UTC
Last updated: 08/05/2026, 22:32:14 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.