bigops-file-storagenpm
bigops-file-storage is a confirmed malicious npm package (MAL-2026-12167) that opens a backdoor for remote access (malicious version 35.1.2). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in bigops-file-storage (npm)
What this malware does
On require() of bigops-file-storage, index.js loads vendor.js which selects a platform-specific asset path, fetches an opaque native binary over HTTPS from attacker-controlled Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf101-adf.workers.dev) with a DNS-TXT chunked fallback under *.sdk.dl.wel1.ru, writes it to a temp cache path, chmods 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd.exe /c start /b. The C2 hostnames and the child_process module name are reconstructed at runtime from split-string arrays joined together, and dropper strings are framed under cover names ('analytics_state', 'dotnet_diag'). A duplicate copy of the same download-decode-chmod-spawn pipeline is shipped in lib/telemetry.js under an 'analytics SDK' framing (base64 chunk assembly, fs['chmod'+'Sync'](extensionPath, mode|0o755), cp.spawn('/bin/sh', ['-c', filePath + ' &'], {detached:true})) as an alternate/staged loader. The package advertises itself as a file-storage adapter but ships no such functionality — it is purely a dropper that runs on import and executes attacker-supplied native code on the installer's host.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Backdoor / remote accessFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for bigops-file-storage (version 35.1.2). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging bigops-file-storage across your stack and pipelines.
If you installed it — respond
bigops-file-storage establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.
Did it already run?
If bigops-file-storage was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks bigops-file-storage before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks bigops-file-storage-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.