@latlongid/location@1.0.1
Malicious code in @latlongid/location (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.004 · DNS
Analysis
The package runs a DNS-based host-identity beacon on install. The postinstall hook executes index.js, which reads the machine's hostname via os.hostname(), hex-encodes it, and embeds it in a DNS lookup to the domain dns[.]gl0b[.]xyz. The query pattern is: {beacon-uuid}.h{hex-hostname}.{random-nonce}.dns[.]gl0b[.]xyz. The beacon UUID is 2d5bccee-3cfd-4d29-9131-2ecddf01d462. The hostname is exfiltrated to the DNS resolver at dns[.]gl0b[.]xyz on every install.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 07:16 AM
- analyzed
- Jul 31, 2026, 07:16 AM
Related advisories
- switchpaymentsapiserv-paypal@2.3.4
- @sapappgyver/appgyver-descriptors@9.9.11
- @cybs_forus/test@1.0.0
- @leviosa86com/leviosa86-test@6.0.0
- ap3-components-ui@9.999.0
- @uwr/colors@1.3.6
- wp-codebox-workspace@9999.99.99
- @dxcl/http-common-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.