-= Per source details. Do not edit below this line.=-
The package presents itself as an ESLint config but on require() unconditionally loads vendor.js, which selects a platform-specific asset, fetches a binary via https.get from string-concatenation-obfuscated Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT chunked-base64 fallback to *.dl.wel1.ru (sdk/ext/pkg/net.dl.wel1.ru). The downloaded bytes are written to /var/tmp or %TEMP% under disguised names (.cache<hex>, dotnetdiag<hex>.exe), chmodded 0755, and spawned detached via cp.spawn('/bin/sh', ['-c', fp+' &'], {detached:true}).unref(). Endpoint strings are assembled from array joins to evade static inspection; a sibling lib/telemetry.js uses require('child_' + 'process') and fs['chmod'+'Sync'] to further hide the sinks. The package name and 'environment config reader' description are unrelated to this behavior. No hash/signature verification, no version pinning, and the hosts are anonymous mutable infrastructure — arbitrary attacker code runs on the installer's host on import.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-05T08:44:52Z",
"id": "IN-MAL-2026-014400",
"import_time": "2026-08-05T09:28:06.5476086Z",
"versions": [
"35.1.9"
],
"source": "amazon-inspector",
"sha256": "706ca9436cb98fc7516d9ccb15e8f55625b73575093bfe0933be786f54ba0667"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-b1lwSy+YdLRwPhQq2yOoocn15mTUOWiLW/a9ye+MIOeu5+VcAfLP0Awcy/2GCyoDyORCPtZHI6UvqL6Ar9q18A==",
"sha1": "abfe9cb66959f1c73ec534bccbb62735f9e4e77a"
},
"filename": "bigops-eslint-config-35.1.9.tgz"
}
],
"evidence_files": [
{
"path": "_vendor.js",
"tlsh": "c8b1b86a05a630094b70dbe4c7175415f65bf6637380c194fb9ca9880fb722482f2efc",
"sha256": "25c168dcc6fd166adb190a64ce3e2938a74617783f268c092f24b801c7b007fc"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bigops-eslint-config/MAL-2026-12164.json"