LWA-2026-7312 confirmed malware

akamaijs@1.0.1

Malicious code in akamaijs (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1102 · Web ServiceT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1005 · Data from Local System

Analysis

akamaijs@1.0.1 is a C2 implant that uses a Google Calendar ICS feed as a dead-drop command channel. On require(), the package fetches a Google Calendar ICS feed ([account]) and parses VEVENT entries for base64-encoded or plain URLs in DESCRIPTION fields. It resolves a primary C2 endpoint from events with SUMMARY matching "akamai" (preferring trycloudflare tunnel URLs) and a secondary staging endpoint from events matching "titi|stage|pkg". A steganographic payload hidden in Unicode variation selectors within a source comment block is extracted and executed via new Function(), receiving the C2 channel function as a parameter. The sensor() function fetches the resolved C2 URL and parses the JSON response. The attacker controls the calendar events to serve new C2 URLs dynamically.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 03:06 AM
analyzed
Aug 1, 2026, 03:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.