Malicious code in bigops-storio-schematics (npm)
The npm package bigops-storio-schematics version 35.3.6 contains malicious code that downloads and executes attacker-controlled native binaries on the installer's machine. It fetches obfuscated payloads from multiple external domains, writes them to temporary files, sets executable permissions, and runs them without any integrity verification. This behavior allows arbitrary code execution during package installation.
AI Analysis
Technical Summary
The bigops-storio-schematics npm package (version 35.3.6) includes a malicious index.js that unconditionally requires a runtime script which selects platform-specific assets and downloads opaque binaries from dynamically reconstructed, string-array-obfuscated hostnames. These binaries are saved to hidden temporary files with randomized names, permissions are set to executable, and the binaries are spawned detached via shell commands. A fallback covert channel uses DNS TXT record queries to fetch base64-encoded payload chunks from multiple domains, concatenates and decodes them into an executable, bypassing HTTP egress filtering. No hash or signature verification is performed, and the payloads originate from attacker-controlled infrastructure, not the legitimate publisher. A sibling telemetry.js file under an analytics-sdk cover story performs a similar staged download and execution chain. Installing or requiring this package results in arbitrary native code execution on the host system.
Potential Impact
This malicious package enables attackers to execute arbitrary native code on the machine of anyone who installs or requires the affected version of bigops-storio-schematics. This can lead to full system compromise, data theft, persistence, or further malware deployment. The lack of integrity checks and use of covert DNS channels increases the stealth and effectiveness of the attack.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or requiring bigops-storio-schematics version 35.3.6. Verify package integrity and source before installation. Consider removing the package if already installed and scanning affected systems for unauthorized binaries or processes spawned from temporary directories. Monitor for updates or advisories from the package maintainer or npm registry regarding this issue. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in bigops-storio-schematics (npm)
Description
The npm package bigops-storio-schematics version 35.3.6 contains malicious code that downloads and executes attacker-controlled native binaries on the installer's machine. It fetches obfuscated payloads from multiple external domains, writes them to temporary files, sets executable permissions, and runs them without any integrity verification. This behavior allows arbitrary code execution during package installation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bigops-storio-schematics npm package (version 35.3.6) includes a malicious index.js that unconditionally requires a runtime script which selects platform-specific assets and downloads opaque binaries from dynamically reconstructed, string-array-obfuscated hostnames. These binaries are saved to hidden temporary files with randomized names, permissions are set to executable, and the binaries are spawned detached via shell commands. A fallback covert channel uses DNS TXT record queries to fetch base64-encoded payload chunks from multiple domains, concatenates and decodes them into an executable, bypassing HTTP egress filtering. No hash or signature verification is performed, and the payloads originate from attacker-controlled infrastructure, not the legitimate publisher. A sibling telemetry.js file under an analytics-sdk cover story performs a similar staged download and execution chain. Installing or requiring this package results in arbitrary native code execution on the host system.
Potential Impact
This malicious package enables attackers to execute arbitrary native code on the machine of anyone who installs or requires the affected version of bigops-storio-schematics. This can lead to full system compromise, data theft, persistence, or further malware deployment. The lack of integrity checks and use of covert DNS channels increases the stealth and effectiveness of the attack.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or requiring bigops-storio-schematics version 35.3.6. Verify package integrity and source before installation. Consider removing the package if already installed and scanning affected systems for unauthorized binaries or processes spawned from temporary directories. Monitor for updates or advisories from the package maintainer or npm registry regarding this issue. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13255
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738521bf8831d5394efa10
Added to database: 08/05/2026, 18:46:57 UTC
Last enriched: 08/05/2026, 22:18:14 UTC
Last updated: 08/05/2026, 22:18:14 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.