Malicious code in bigops-tinkoff-telephony-mock (npm)
The npm package bigops-tinkoff-telephony-mock version 35.5.1 contains malicious code that downloads and executes a platform-specific binary from external Cloudflare Workers hosts without verification. This binary is disguised as .NET diagnostics files and executed on the host system, enabling remote code execution. The package also includes a fake telemetry SDK that bundles the same dropper. Any system installing or importing this package is fully compromised, risking exposure of all stored secrets and keys.
AI Analysis
Technical Summary
The bigops-tinkoff-telephony-mock npm package (version 35.5.1) contains malicious code that, upon require(), loads a runtime script which fetches a platform-specific binary from Cloudflare Workers hosts reconstructed at runtime from split string fragments, with a fallback covert DNS TXT channel. The fetched binary is saved to temporary directories under disguised filenames, made executable, and run detached via shell commands. No hash or signature verification is performed, and the hosts are unrelated to the package publisher. Additionally, a fake telemetry SDK bundled in the package contains the same dropper. This results in full remote code execution on any machine that installs or imports the package.
Potential Impact
Systems that install or run this package are fully compromised, as the malicious code executes arbitrary binaries with no verification. This can lead to complete system takeover, exposure of secrets and keys stored on the machine, and persistent unauthorized access. Removal of the package alone does not guarantee eradication of all malicious components.
Mitigation Recommendations
Remove the bigops-tinkoff-telephony-mock package version 35.5.1 immediately from all affected systems. Rotate all secrets and keys stored on compromised machines from a secure, unaffected environment. Because the package executes arbitrary code without verification, assume full system compromise and perform thorough incident response and remediation. No official patch or fix is available; avoid using this package version entirely.
Malicious code in bigops-tinkoff-telephony-mock (npm)
Description
The npm package bigops-tinkoff-telephony-mock version 35.5.1 contains malicious code that downloads and executes a platform-specific binary from external Cloudflare Workers hosts without verification. This binary is disguised as .NET diagnostics files and executed on the host system, enabling remote code execution. The package also includes a fake telemetry SDK that bundles the same dropper. Any system installing or importing this package is fully compromised, risking exposure of all stored secrets and keys.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bigops-tinkoff-telephony-mock npm package (version 35.5.1) contains malicious code that, upon require(), loads a runtime script which fetches a platform-specific binary from Cloudflare Workers hosts reconstructed at runtime from split string fragments, with a fallback covert DNS TXT channel. The fetched binary is saved to temporary directories under disguised filenames, made executable, and run detached via shell commands. No hash or signature verification is performed, and the hosts are unrelated to the package publisher. Additionally, a fake telemetry SDK bundled in the package contains the same dropper. This results in full remote code execution on any machine that installs or imports the package.
Potential Impact
Systems that install or run this package are fully compromised, as the malicious code executes arbitrary binaries with no verification. This can lead to complete system takeover, exposure of secrets and keys stored on the machine, and persistent unauthorized access. Removal of the package alone does not guarantee eradication of all malicious components.
Defensive Guidance
Remove the bigops-tinkoff-telephony-mock package version 35.5.1 immediately from all affected systems. Rotate all secrets and keys stored on compromised machines from a secure, unaffected environment. Because the package executes arbitrary code without verification, assume full system compromise and perform thorough incident response and remediation. No official patch or fix is available; avoid using this package version entirely.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12847
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-92wj-cj5h-gp6p"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a74cfaebf8831d5391b23c9
Added to database: 08/06/2026, 18:17:18 UTC
Last enriched: 08/06/2026, 19:34:47 UTC
Last updated: 08/06/2026, 19:34:47 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.