LWA-2026-12227 MAL-2026-16292 ↗ confirmed malware

@shared-web/utils@9.9.10

Malicious code in @shared-web/utils (npm)

Analysis

The install hook (node index.js) runs an obfuscated beacon. It reads the OS username, hostname, and current working directory basename, then exfiltrates them via a DNS resolve4 query to the attacker-controlled domain oob[.]algamil7x[.]xyz, encoded as <prefix>.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz. The package otherwise presents as a legitimate asset/util library.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 08:24 AM
analyzed
Sep 18, 2026, 07:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.