@tvg-mar/tvg-promos-atomic-ui@9.9.10
Malicious code in @tvg-mar/tvg-promos-atomic-ui (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1048 · Exfiltration Over Alternative Protocol
Analysis
The package's install hook (node index.js) runs a runtime bootstrap that collects the host's username, hostname, current working directory name, and a timestamp, encodes them into a DNS query string, and sends them to the attacker-controlled domain tvguioob[.]algamil7x[.]xyz via a dns.resolve4 lookup. The domain is charcode-obfuscated inside runtime/support/telemetry/probe/c3f7a9.js. The package is presented as a UI component library but the install-time beacon exfiltrates host metadata to the remote domain.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 05:56 PM
- analyzed
- Sep 22, 2026, 05:58 PM
Related advisories
- @tvg-mar/utils@9.9.10
- @tvg-mar/storyblok-bridge@9.9.9
- @tvg-mar/promos-gtm@9.9.10
- siriusbeyond@1.0.0
- @hzero-front-ui/hzero-ui@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.