@dxcl/account-js@99.99.99
Malicious code in @dxcl/account-js (npm)
Analysis
The package @dxcl/account-js at version 99.99.99 is a dependency-confusion stub with no functional code (index.js exports an empty object). Its preinstall and install hooks collect system identity (whoami, hostname, current working directory) and exfiltrate it via HTTP GET and DNS query to callback[.]m0chan[.]co[.]uk. The script builds two exfiltration channels: an HTTPS request to hxxps://<base64-package-name>.callback[.]m0chan[.]co[.]uk/<base64-of-whoami:hostname:pwd:package_name>, and a DNS nslookup to <base64-package-name>.<slug-package-name>.callback[.]m0chan[.]co[.]uk. The C2 host is callback[.]m0chan[.]co[.]uk.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 11:21 AM
- analyzed
- Jun 18, 2026, 11:22 AM
Related advisories
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/indicators-js@99.99.99
- @dxcl/customer-js@99.99.99
- ug-env-switch-ball@7.9.9
- mw-filesystem-events-nodream_compat@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.