LWA-2026-12229 MAL-2026-16283 ↗ confirmed malware

@shared-web/assets@9.9.10

Malicious code in @shared-web/assets (npm)

Analysis

The install hook (node index.js) runs an obfuscated beacon. It reads the OS username, hostname, and current working directory basename, then exfiltrates them via a DNS resolve4 query to the attacker-controlled domain oob[.]algamil7x[.]xyz, encoded as <prefix>.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz. The package otherwise presents as a legitimate asset/util library.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 08:26 AM
analyzed
Sep 18, 2026, 07:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.