@sapappgyver/appgyver-descriptors@9.9.11
Malicious code in @sapappgyver/appgyver-descriptors (npm)
Analysis
@sapappgyver/appgyver-descriptors@9.9.11 is a combosquat package impersonating SAP AppGyver. On install, the package runs an obfuscated beacon in lib/core.js that collects the installer's username, hostname, current working directory, and current timestamp, then exfiltrates this host metadata via a DNS query to oob[.]sl4x0[.]xyz. The DNS query format is: {prefix}.{username}.{hostname}.{cwd}.{timestamp}.oob[.]sl4x0[.]xyz. The package ships legitimate-looking utility code in src/ as cover, while the obfuscated payload resides in lib/6ad264.js, lib/b02e30.js, and lib/core.js. The publisher email ([account]) shares the C2 domain. No credential or token theft was observed — the payload is a host-metadata beacon only.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 10:11 PM
- analyzed
- Jul 28, 2026, 10:57 PM
Related advisories
- @cybs_forus/test@1.0.0
- @leviosa86com/leviosa86-test@6.0.0
- ap3-components-ui@9.999.0
- @uwr/colors@1.3.6
- wp-codebox-workspace@9999.99.99
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/user-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.