@consts/links@9.9.9
Malicious code in @consts/links (npm)
Analysis
The package's install hook (node index.js) runs a hidden beacon in lib/core.js. On install it reads the victim's OS username, hostname, and current working directory, then encodes them into a DNS query of the form links.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz and performs a DNS lookup against that domain, exfiltrating host identity to the attacker-controlled domain oob[.]algamil7x[.]xyz. The runtime modules (os, dns, process) are loaded through module.constructor._load to bypass require hooks, and the domain is stored as byte arrays in lib/b02e30.js to hide it from string scans.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 06:48 PM
- analyzed
- Sep 14, 2026, 06:50 PM
Related advisories
- devplatform-auth-client@35.2.1
- oc-navbar-module-client@9.9.10
- @insiderintelligence/componentlibrary@9.9.10
- test899-auth@1.0.1
- quartz-core@99.1.9
- message-compiler@9.2.0
- @finaxis/common-js@0.3.3
- sme-rko-finance-front-operations-notifications-impl@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.