LWA-2026-12306 MAL-2026-16353 ↗ confirmed malware

@insiderintelligence/componentlibrary@9.9.10

Malicious code in @insiderintelligence/componentlibrary (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1048.003 · Exfiltration Over Alternative ProtocolT1027 · Obfuscated Files or Information

Analysis

The install hook runs node index.js, which bootstraps a runtime that executes a DNS-exfiltration beacon. The beacon collects the OS username, hostname, current working directory basename, and a Unix timestamp, then encodes them into a DNS query of the form iiclib.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz and resolves it, leaking host identity to the attacker-controlled domain oob[.]algamil7x[.]xyz. The payload is obfuscated with byte-array string decoding and loads modules via module.constructor._load to bypass standard require auditing.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 12:40 AM
analyzed
Sep 24, 2026, 06:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.