LWA-2026-12324 MAL-2026-16412 ↗ confirmed malware

@tvg-mar/promos-context@9.9.10

Malicious code in @tvg-mar/promos-context (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

The package's install hook (node index.js) executes a hidden telemetry probe that collects the installer's OS username, hostname, current working directory name, and a timestamp, then exfiltrates them by issuing a DNS resolve4 query to the attacker-controlled domain oob[.]algamil7x[.]xyz (query format: tvgctx.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz). The probe strings are char-code-obfuscated and modules are loaded dynamically to evade detection. The package is otherwise a small promos-context library; the beacon runs on install regardless of whether the library is used.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 01:55 PM
analyzed
Sep 22, 2026, 01:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.