akamai-sensorv1@1.0.0
Malicious code in akamai-sensorv1 (npm)
Analysis
Combosquat package impersonating Akamai. Contains a multi-stage C2 implant: (1) A hidden payload is steganographically encoded using Unicode variation selectors inside a comment in index.js; sync-metrics.js decodes and executes it via dynamic code evaluation. (2) The visible code fetches a Google Calendar ICS feed (calendar[.]google[.]com/calendar/ical/[account]/public/basic.ics), extracts a URL from the DESCRIPTION field of calendar events, appends /generate, and fetches JSON from that URL — a dead-drop C2 channel where the attacker controls the calendar to dynamically change the command server. At runtime the package performed a DNS sandbox-evasion check before executing its payload. No repository URL provided.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 11:08 AM
- analyzed
- Jul 30, 2026, 11:12 AM
Related advisories
- tinkoff-pfp-atom-desktop-carousel@20.8.8
- sort-btree@2.1.4
- streak-view-core@1.0.0
- system-performance-helper@1.0.1
- quickbuf@1.0.1
- terminal-kit-tslint-config@20.1.9
- pfp-forms-sme-loan@20.2.1
- tinkoff-fb-service-prefill-profile-contact@20.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.