OpenSSF/OSV advisory MAL-2026-12151 confirms this npm version as malicious. On require() of bigops-auth-interceptor@35.7.2, index.js loads _vendor.js which selects a platform-specific binary URL, downloads bytes over HTTPS from one of four string-concatenation-obfuscated Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev), writes them to a temp path under a disguised name...
This report applies to bigops-auth-interceptor@35.7.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.