akamai-sensorv2@1.0.0
Malicious code in akamai-sensorv2 (npm)
Analysis
akamai-sensorv2 is a combosquat trojan impersonating Akamai security tools. It contains a hidden payload encoded as Unicode variation selectors inside a comment block in index.js, decoded and executed at runtime via `new Function("require", ...)`. The package reads a Google Calendar ICS feed ([account]) to dynamically resolve a C2 URL from calendar event descriptions, then fetches and executes JSON payloads from that URL with "/generate" appended. The attacker controls the calendar events and can change the C2 endpoint at any time without updating the package. The hidden payload has full filesystem and network access via the passed `require` function.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 12:08 PM
- analyzed
- Jul 30, 2026, 12:10 PM
Related advisories
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-int-lib@1.0.0
- @types-beta/sdk@0.1.3
- postcss-motion-utils@3.2.7
- @ghost_debugger/nanocache@0.1.1
- fluid-type-ui@2.0.8
- chai-as-rendered@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.