LWA-2026-12130 MAL-2026-17202 ↗ confirmed malware

@consts/links@9.9.9

Malicious code in @consts/links (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1048.003 · Exfiltration Over Alternative ProtocolT1567 · Exfiltration Over Web Service

Analysis

The package's install hook (node index.js) runs a hidden beacon in lib/core.js. On install it reads the victim's OS username, hostname, and current working directory, then encodes them into a DNS query of the form links.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz and performs a DNS lookup against that domain, exfiltrating host identity to the attacker-controlled domain oob[.]algamil7x[.]xyz. The runtime modules (os, dns, process) are loaded through module.constructor._load to bypass require hooks, and the domain is stored as byte arrays in lib/b02e30.js to hide it from string scans.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 06:48 PM
analyzed
Sep 14, 2026, 06:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.