LWA-2026-7277 MAL-2026-12139 ↗ confirmed malware

akamai-sensorv3@1.0.0

Malicious code in akamai-sensorv3 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1027.010 · Command ObfuscationT1102 · Web ServiceT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Combosquat of the Akamai brand. The package is a multi-stage C2 implant. On require(), sync-metrics.js reads a Unicode variation-selector-encoded payload hidden in a comment inside index.js, decodes it, and executes it via new Function. The main module fetches a Google Calendar iCal feed (calendar[.]google[.]com/calendar/ical/[account]/public/basic.ics) and extracts a remote generator URL from the calendar's DESCRIPTION fields, then fetches that URL over HTTP/HTTPS and parses the response as JSON. The package attempted DNS egress to an external host. The payload is a remote-code-execution implant using a Google Calendar dead-drop as its C2 resolver.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 03:59 PM
analyzed
Jul 30, 2026, 04:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.