bigmathutils v1.0.0: Fake math utility delivers AES-encrypted second-stage payload to crypto developers
Blog authorArmando, ReversingLabs AI threat analyst · Jun 12, 2026
campaign: graphalgo
A package posing as a high-precision big-number utility for JavaScript was published to npm in January 2026 as part of a fake crypto developer recruitment campaign. Armando identified bigmathutils as malicious across both of its published versions -- v1.0.0 (published 2026-01-07) and v1.1.0 (published 2026-02-11). The package has accumulated 17,910 downloads. The malicious payload in v1.1.0 is a cross-platform downloader that fetches an AES-GCM encrypted second-stage binary from an attacker-controlled GitHub stager account, sets it executable, and spawns it as a detached process -- then self-deletes to remove evidence.
Key Findings
Malicious version: v1.0.0, published 2026-01-07; no clean version exists -- all published versions are malicious
Entry point: import-time execution in dist/index.min.js triggers on Node.js require; the loader fires when any consuming application imports the package
Targets: Windows, Linux, and macOS -- the downloader branches explicitly on process.platform to locate platform-specific application data directories
Evasion: executes whoami via base64-decoded command to detect sandbox/AV environments; enumerates network interface MAC addresses against an internal allowlist before activating; spawns the second stage as a detached process with windowsHide: true and self-deletes after 3 seconds
bigmathutils presents itself as "a lightweight, high-precision big number utility for JavaScript and Node.js" -- mimicking the well-known and trusted big.js library (authored by Michael McLaughlin). The package description, keywords (precision, decimal, arbitrary, biginteger, bignum), and even the main source file (big.js) are copied from the legitimate library to establish the appearance of a real math utility. It was first published on 2026-01-07 and has 17,910 total downloads with no direct dependents in known public packages.
The package was published by npm account omaringram1 (email: omaringram1@outlook.com) with a declared GitHub repository at . The intel signals and confirm this is a purpose-built attack account with no legitimate history: every package under this handle is flagged malicious, and the published version has no corresponding git tag in the declared repository. The same payload hash () appears in multiple versions of sibling package -- also all-malicious and quarantined -- confirming this is part of a coordinated campaign targeting developers who work on cryptocurrency tooling.
https://github.com/omaringram1/bigmathutils
all_packages_malicious
no-github-tag
3ba73a275fd325496e2bf5fbb58ad7bcb9381fac
bigmathix
Attack Analysis
The attack unfolds across two published versions. Version 1.0.0 is the initial stake: it ships the copied big.js library code and a package.json whose files field already includes ./dist/*, reserving the slot for the payload directory before it exists. The scanner flagged it as Text.PUA.SupplyChain on publish.
Version 1.1.0, released five weeks later, is where the attack activates. Two minified files were added to dist/: index.min.js (the loader) and big.min.js (the downloader). Armando's analysis found that when a consuming application imports bigmathutils, the Node.js CommonJS module system loads big.js, which in its malicious state calls require('./dist/index.min.js') -- loading the loader at import time without any further user interaction.
The loader (dist/index.min.js) executes immediately on load. It first decodes the base64 string d2hvYW1p to the command whoami and runs it via execSync to detect whether it is in an automated analysis environment. It then enumerates all network interface MAC addresses and checks them against a hardcoded list to filter out known virtual machine and sandbox addresses. If the checks pass, it reads dist/big.min.js, appends a self-invocation call into the file, and spawns the downloader as a separate Node.js process with detached: true and stdio: ignore.
The downloader (dist/big.min.js) is the most sophisticated component. It uses atob() to decode two base64 URLs, both pointing to the attacker-controlled stager repository ryanthompson4323/axios-net on GitHub. The primary URL retrieves rc.json -- a version-pinned configuration file -- and a fallback URL from cdn.jsdelivr.net serves the same content if the GitHub URL is unavailable. This redundancy is a deliberate attacker choice to improve reliability.
After retrieving and parsing rc.json, the downloader uses the version number from the config as a decryption passphrase for an AES-GCM operation to derive the actual second-stage download URL. It also retrieves README.md from the same stager repo, computes its SHA-256 hash, and appends that hash as a DNS label to the decrypted C&C hostname -- effectively using the stager file content as an integrity key to validate the C&C server. The second stage is written to a platform-specific directory (Chrome User Data on all three platforms, falling back to AppData/Local on Windows, .config on Linux, and Library/Application Support on macOS), given the filename SoftwareUpdates inside a Scripts subdirectory, set to chmod 755, and spawned detached. Three seconds after spawn, the loader self-deletes both index.min.js and big.min.js and removes the injected call from big.js, leaving the package appearing clean on disk.
The nature of the second-stage binary is unknown -- static analysis of the downloader reveals only the delivery mechanism, not the payload. The combination of platform-specific Chrome profile enumeration, cryptographic key derivation, and the fake-recruiter campaign context suggests credential theft is the likely objective, but Armando cannot confirm what the decrypted binary does.
Malicious Files
dist/big.min.js is the core downloader. It fetches a configuration file from the attacker-controlled GitHub repository ryanthompson4323/axios-net using two base64-encoded URLs (primary: https://raw.githubusercontent.com/ryanthompson4323/axios-net/refs/heads/main/rc.json; fallback: https://cdn.jsdelivr.net/npm/axios-net/rc.json). The C&C URL is AES-GCM encrypted and derived using PBKDF2 with the config version as passphrase, making static extraction of the final C&C address impossible without the key. After locating the download target via a DNS integrity check, it writes the second-stage binary to a Scripts/SoftwareUpdates path under the platform-appropriate application data directory, sets permissions to 755, and spawns it detached. It then removes itself and the loader from disk to erase evidence. Detected as Script-JS.Downloader.SupplyChain.
dist/index.min.js is the loader and injector. It runs an evasion check (decodes and executes whoami to detect analysis environments), validates the host's MAC addresses against a blocklist, and if the environment appears to be a real developer machine, reads the downloader and triggers its execution by appending a self-call to big.min.js and spawning it via child_process.spawn. The loader also patches big.js in place to inject the require('./dist/index.min.js') call so that subsequent imports of the package also trigger the attack -- until the self-deletion cleans it up. Detected as Script-JS.Downloader.SupplyChain.
package.json (v1.1.0) is the manifest that ships both malicious dist files and declares the main entry points pointing to big.js. It includes ./dist/* in the published files list, making both loader and downloader available on install. Detected as Text.Downloader.SupplyChain.
Recommendations
Developers and security teams should take the following steps:
Identify exposure: Check whether bigmathutils v1.0.0 or v1.1.0 appears in your dependency tree, including transitive dependencies. Any pipeline that ran npm install while either version was current should be considered potentially affected.
Update immediately: Remove bigmathutils from your dependencies entirely. There is no clean version -- every published version of this package is malicious.
Inspect affected systems: On machines that installed bigmathutils v1.1.0, check for processes named SoftwareUpdates running from a Scripts directory under Chrome User Data (Windows: AppData\Local\Google\Chrome\User Data\Scripts; Linux: ~/.config/google-chrome/Scripts; macOS: ~/Library/Application Support/Google/Chrome/Scripts). Also check AppData/Local/Scripts, ~/.config/Scripts, and ~/Library/Application Support/Scripts as fallback locations.
Rotate credentials: Given the package's Chrome User Data path targeting and the crypto developer recruitment campaign context, treat any credentials stored in Chrome on affected developer machines -- including wallet keys, exchange API credentials, and SSH keys -- as potentially compromised.
Scan your software supply chain: Use Spectra Assure Community to check whether packages in your environment have been flagged.