tdhg-demp@1.0.0
Malicious code in tdhg-demp (npm)
Analysis
tdhg-demp@1.0.0 is a trojanized snake game. The package ships legitimate game code as cover, but both the npm preinstall lifecycle hook (check-environment.js) and the game constructor call a hex-obfuscated function (initSystem in utils.js). At install time and runtime, the function collects the victim's system fingerprint (username via os.userInfo().username, hostname via os.hostname(), external IP via api[.]ipify[.]org / api[.]myip[.]com / ifconfig[.]me, and DNS server configuration), hex-encodes it, and exfiltrates the data by crafting a DNS A-record lookup to the subdomain pattern `<hex-encoded-fingerprint>.c535bfb2[.]gfde[.]site`. The DNS query leaks the collected data to the DNS server for gfde[.]site. The publisher's email address uses the same gfde[.]site domain.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 05:02 PM
- analyzed
- Jun 14, 2026, 05:03 PM
Related advisories
- sftc-advance-components@0.9.9
- rtms-manager@1.0.0
- reseller-app@9.9.11
- rendezvous-js@9.9.11
- qr-code-styling-temp@9.9.10
- atlassian-forge-skills@29.1.0
- poloman@9.2.1
- paypal-examples-openai@99.99.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.