@hoteldev/common@1.0.9
Malicious code in @hoteldev/common (npm)
Analysis
@hoteldev/common@1.0.9 ships an obfuscated payload in build/index.js (eval(atob(...))) that installs a command-and-control implant. On load it queries public Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) and the eth[.]blockscout[.]com API to locate transactions from a hardcoded address (0xa3322e5f3d331d330e6f0121063e9adc2490e5f1a), extracting IP addresses from transaction fields to derive C2 hosts. It then spawns a detached node process that connects to hxxp://{ip}:443/0x/cls and hxxp://{ip}:443/0x/ls, XOR-decoding command responses carried in the x-payload-b64 HTTP header. The implant uses the Ethereum blockchain as a covert channel to distribute its C2 infrastructure.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 10:06 AM
- analyzed
- Aug 5, 2026, 10:09 AM
Related advisories
- @vboxdev/common@1.0.73
- streak-calc-metrics@1.0.0
- tailwind-hide-scrollbar@2.1.5
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- @nasdtickets/common@1.0.23
- tailwindcss-scrollbar-hide@2.2.6
- @tuluax/errb@3.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.