LWA-2026-11808 MAL-2026-15671 ↗ confirmed malware

quartz-core@99.1.9

Malicious code in quartz-core (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (node index.js) runs a DNS-based host-identity beacon on install. It reads the installer's username, hostname, and current working directory, encodes them into subdomains, and sends a DNS query of the form selftest.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz to the attacker-controlled domain oob[.]algamil7x[.]xyz. The host metadata is exfiltrated out-of-band over DNS, evading HTTP-based detection. The package has no repository and no declared purpose.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 09:06 PM
analyzed
Aug 31, 2026, 09:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.