LWA-2026-12246 MAL-2026-16290 ↗ confirmed malware

@insiderintelligence/googleadmanager@9.9.10

Malicious code in @insiderintelligence/googleadmanager (npm)

Analysis

The package's install script (node index.js) runs an obfuscated beacon on install. It reads the OS username, hostname, and current working directory, then encodes them with a timestamp into a DNS query of the form iadgm.<user>.<host>.<cwd>.<ts>.oob[.]algamil7x[.]xyz and resolves it via dns.resolve4, exfiltrating host metadata to the attacker-controlled domain oob[.]algamil7x[.]xyz. The beacon loads the os and dns modules through module.constructor._load to bypass the standard require chain, and the package bundles benign-looking Google Ad Manager slot components as a decoy.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 05:02 PM
analyzed
Sep 18, 2026, 09:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.