LWA-2026-7246 MAL-2026-13216 ↗ confirmed malware

akamai-sensorv1@1.0.0

Malicious code in akamai-sensorv1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1027.013 · Encrypted/Encoded FileT1102 · Web ServiceT1102.003 · One-Way CommunicationT1105 · Ingress Tool TransferT1497.001 · System Checks

Analysis

Combosquat package impersonating Akamai. Contains a multi-stage C2 implant: (1) A hidden payload is steganographically encoded using Unicode variation selectors inside a comment in index.js; sync-metrics.js decodes and executes it via dynamic code evaluation. (2) The visible code fetches a Google Calendar ICS feed (calendar[.]google[.]com/calendar/ical/[account]/public/basic.ics), extracts a URL from the DESCRIPTION field of calendar events, appends /generate, and fetches JSON from that URL — a dead-drop C2 channel where the attacker controls the calendar to dynamically change the command server. At runtime the package performed a DNS sandbox-evasion check before executing its payload. No repository URL provided.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 11:08 AM
analyzed
Jul 30, 2026, 11:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.