akamai-sensorv3@1.0.0
Malicious code in akamai-sensorv3 (npm)
Analysis
Combosquat of the Akamai brand. The package is a multi-stage C2 implant. On require(), sync-metrics.js reads a Unicode variation-selector-encoded payload hidden in a comment inside index.js, decodes it, and executes it via new Function. The main module fetches a Google Calendar iCal feed (calendar[.]google[.]com/calendar/ical/[account]/public/basic.ics) and extracts a remote generator URL from the calendar's DESCRIPTION fields, then fetches that URL over HTTP/HTTPS and parses the response as JSON. The package attempted DNS egress to an external host. The payload is a remote-code-execution implant using a Google Calendar dead-drop as its C2 resolver.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 03:59 PM
- analyzed
- Jul 30, 2026, 04:06 PM
Related advisories
- ai-pro-sdk@2.0.3
- ultra-base64-math@1.0.2
- ui-core-system@1.0.3
- @servicetitan/anvil2-ext-mwv@0.0.9
- akamai-sensorv1@1.0.0
- streak-metric-core@1.0.0
- express-middle@5.5.1
- chai-as-map@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.