Miscreants are exploiting expired Amazon Web Service (AWS) buckets to place malicious code in legitimate packages on the npm repository. The bignum package is one of several releases on npm that has been found to be vulnerable to this type of attack.