LWA-2026-12382 MAL-2026-17154 ↗ confirmed malware

@nf-addons/am-global-header@9.9.10

Malicious code in @nf-addons/am-global-header (npm)

T1082 · System Information DiscoveryT1071.004 · DNST1048 · Exfiltration Over Alternative ProtocolT1059.007 · JavaScript

Analysis

The package's install hook (node index.js) runs a hidden telemetry probe at install time. The probe reads the installing user's OS username, hostname, and current working directory, then encodes them into a DNS query of the form nfamh.<username>.<hostname>.<cwd>.<timestamp>.oob[.]algamil7x[.]xyz and resolves it, exfiltrating host identity metadata to the attacker-controlled domain oob[.]algamil7x[.]xyz. The behaviour is obfuscated with character-code arrays and a dynamic module loader, and the package README falsely states it makes no network requests. No credentials or tokens are collected; the payload is a host-metadata beacon.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 09:05 AM
analyzed
Sep 24, 2026, 09:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.