LWA-2026-7297 MAL-2026-12506 ↗ confirmed malware

@latlongid/location@1.0.1

Malicious code in @latlongid/location (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.004 · DNS

Analysis

The package runs a DNS-based host-identity beacon on install. The postinstall hook executes index.js, which reads the machine's hostname via os.hostname(), hex-encodes it, and embeds it in a DNS lookup to the domain dns[.]gl0b[.]xyz. The query pattern is: {beacon-uuid}.h{hex-hostname}.{random-nonce}.dns[.]gl0b[.]xyz. The beacon UUID is 2d5bccee-3cfd-4d29-9131-2ecddf01d462. The hostname is exfiltrated to the DNS resolver at dns[.]gl0b[.]xyz on every install.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 07:16 AM
analyzed
Jul 31, 2026, 07:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.