LWA-2026-12330 MAL-2026-16415 ↗ confirmed malware

@tvg-mar/tvg-promos-atomic-ui@9.9.10

Malicious code in @tvg-mar/tvg-promos-atomic-ui (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1048 · Exfiltration Over Alternative Protocol

Analysis

The package's install hook (node index.js) runs a runtime bootstrap that collects the host's username, hostname, current working directory name, and a timestamp, encodes them into a DNS query string, and sends them to the attacker-controlled domain tvguioob[.]algamil7x[.]xyz via a dns.resolve4 lookup. The domain is charcode-obfuscated inside runtime/support/telemetry/probe/c3f7a9.js. The package is presented as a UI component library but the install-time beacon exfiltrates host metadata to the remote domain.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 05:56 PM
analyzed
Sep 22, 2026, 05:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.