@nf-addons/am-global-header@9.9.10
Malicious code in @nf-addons/am-global-header (npm)
Analysis
The package's install hook (node index.js) runs a hidden telemetry probe at install time. The probe reads the installing user's OS username, hostname, and current working directory, then encodes them into a DNS query of the form nfamh.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz and resolves it, exfiltrating host identity metadata to the attacker-controlled domain oob[.]algamil7x[.]xyz. The behaviour is obfuscated with character-code arrays and a dynamic module loader, and the package README falsely states it makes no network requests. No credentials or tokens are collected; the payload is a host-metadata beacon.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 09:05 AM
- analyzed
- Sep 24, 2026, 09:07 AM
Related advisories
- @tvg-mar/tvg-promos-atomic-ui@9.9.10
- siriusbeyond@1.0.0
- @hzero-front-ui/hzero-ui@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
- hunsterx-package@7.0.1
- search-from-feed@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.