@tvg-mar/promos-context@9.9.10
Malicious code in @tvg-mar/promos-context (npm)
Analysis
The package's install hook (node index.js) executes a hidden telemetry probe that collects the installer's OS username, hostname, current working directory name, and a timestamp, then exfiltrates them by issuing a DNS resolve4 query to the attacker-controlled domain oob[.]algamil7x[.]xyz (query format: tvgctx.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz). The probe strings are char-code-obfuscated and modules are loaded dynamically to evade detection. The package is otherwise a small promos-context library; the beacon runs on install regardless of whether the library is used.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 01:55 PM
- analyzed
- Sep 22, 2026, 01:57 PM
Related advisories
- @tvg-mar/utils@9.9.10
- @tvg-mar/tvg-promos-atomic-ui@9.9.10
- @tvg-mar/storyblok-bridge@9.9.9
- @tesla-insurance/vinless-quote@9.9.10
- test899-auth@1.0.1
- test89-auth@1.0.1
- @tink/tink-link-core@9.9.10
- test89078-auth@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.