@insiderintelligence/componentlibrary@9.9.10
Malicious code in @insiderintelligence/componentlibrary (npm)
Analysis
The install hook runs node index.js, which bootstraps a runtime that executes a DNS-exfiltration beacon. The beacon collects the OS username, hostname, current working directory basename, and a Unix timestamp, then encodes them into a DNS query of the form iiclib.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz and resolves it, leaking host identity to the attacker-controlled domain oob[.]algamil7x[.]xyz. The payload is obfuscated with byte-array string decoding and loads modules via module.constructor._load to bypass standard require auditing.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 12:40 AM
- analyzed
- Sep 24, 2026, 06:21 AM
Related advisories
- @insiderintelligence/googleadmanager@9.9.10
- test899-auth@1.0.1
- @consts/links@9.9.9
- devplatform-auth-client@35.2.1
- oc-navbar-module-client@9.9.10
- @tvg-mar/promos-context@9.9.10
- @tesla-insurance/vinless-quote@9.9.10
- test89-auth@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.