LWA-2026-7274 MAL-2026-13217 ↗ confirmed malware

akamai-sensorv2@1.0.0

Malicious code in akamai-sensorv2 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1001 · Data Obfuscation

Analysis

akamai-sensorv2 is a combosquat trojan impersonating Akamai security tools. It contains a hidden payload encoded as Unicode variation selectors inside a comment block in index.js, decoded and executed at runtime via `new Function("require", ...)`. The package reads a Google Calendar ICS feed ([account]) to dynamically resolve a C2 URL from calendar event descriptions, then fetches and executes JSON payloads from that URL with "/generate" appended. The attacker controls the calendar events and can change the C2 endpoint at any time without updating the package. The hidden payload has full filesystem and network access via the passed `require` function.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 12:08 PM
analyzed
Jul 30, 2026, 12:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.