@shared-web/assets@9.9.10
Malicious code in @shared-web/assets (npm)
Analysis
The install hook (node index.js) runs an obfuscated beacon. It reads the OS username, hostname, and current working directory basename, then exfiltrates them via a DNS resolve4 query to the attacker-controlled domain oob[.]algamil7x[.]xyz, encoded as <prefix>.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz. The package otherwise presents as a legitimate asset/util library.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:26 AM
- analyzed
- Sep 18, 2026, 07:05 PM
Related advisories
- @shared-web/utils@9.9.10
- @shared-web/constants@9.9.9
- @shared-web/modules@9.9.9
- sbironman@1.0.0
- ded-aa-common-ded-aa-common-core@35.1.6
- bnpl-blocks-independent-bnpl-open-api@35.1.2
- bigops-api@35.8.8
- dolyame-ui-loader@35.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.