@shared-runtime/modules@9.9.10
Malicious code in @shared-runtime/modules (npm)
Analysis
The package's install script (node index.js) runs an obfuscated beacon on install. It reads the OS username, hostname, and current working directory, then encodes them with a timestamp into a DNS query of the form srmods.<user>.<host>.<cwd>.<ts>.oob[.]algamil7x[.]xyz and resolves it via dns.resolve4, exfiltrating host metadata to the attacker-controlled domain oob[.]algamil7x[.]xyz. The beacon loads the os and dns modules through module.constructor._load to bypass the standard require chain, and the package bundles benign-looking financial-workflow modules as a decoy.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:22 AM
- analyzed
- Sep 18, 2026, 09:11 PM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.