LWA-2026-7204 MAL-2026-12507 ↗ confirmed malware

@sapappgyver/appgyver-descriptors@9.9.11

Malicious code in @sapappgyver/appgyver-descriptors (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@sapappgyver/appgyver-descriptors@9.9.11 is a combosquat package impersonating SAP AppGyver. On install, the package runs an obfuscated beacon in lib/core.js that collects the installer's username, hostname, current working directory, and current timestamp, then exfiltrates this host metadata via a DNS query to oob[.]sl4x0[.]xyz. The DNS query format is: {prefix}.{username}.{hostname}.{cwd}.{timestamp}.oob[.]sl4x0[.]xyz. The package ships legitimate-looking utility code in src/ as cover, while the obfuscated payload resides in lib/6ad264.js, lib/b02e30.js, and lib/core.js. The publisher email ([account]) shares the C2 domain. No credential or token theft was observed — the payload is a host-metadata beacon only.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 10:11 PM
analyzed
Jul 28, 2026, 10:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.