npm package bigmathix and the BigSquatRat campaign behind it

2026-01-19 Kmsec

https://kmsec.uk/blog/js-malware-bigmathix/

Thumbnail for npm package bigmathix and the BigSquatRat campaign behind it

A malicious npm package named bigmathix impersonated the legitimate big.js library and introduced malicious version 1.0.2 after two benign releases and more than 20 days of dwell time. The package, published by jacksonroman338, used an obfuscated multi-stage Node.js infection chain that launched dist/big.min.js and relied on dynamic variables to hinder immediate deobfuscation. The campaign used GitHub infrastructure, DNS resolution, base64 encoding, SHA-256-derived values, and encryption to conceal the next-stage payload URL. The identified infrastructure included C2 domain aurevian.cloud and attacker-controlled npm packages axios-net, bigmathix, bigmathex, bignumx, and bigmathutils. Although the original analysis withheld attribution, later ReversingLabs evidence tied the activity strongly to FAMOUS CHOLLIMA's Contagious Interview campaign.

Related Reports

2026-04-17 • 30% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tag: T1082
« Back