akamaijs@1.0.1
Malicious code in akamaijs (npm)
Analysis
akamaijs@1.0.1 is a C2 implant that uses a Google Calendar ICS feed as a dead-drop command channel. On require(), the package fetches a Google Calendar ICS feed ([account]) and parses VEVENT entries for base64-encoded or plain URLs in DESCRIPTION fields. It resolves a primary C2 endpoint from events with SUMMARY matching "akamai" (preferring trycloudflare tunnel URLs) and a secondary staging endpoint from events matching "titi|stage|pkg". A steganographic payload hidden in Unicode variation selectors within a source comment block is extracted and executed via new Function(), receiving the C2 channel function as a parameter. The sensor() function fetches the resolved C2 URL and parses the JSON response. The attacker controls the calendar events to serve new C2 URLs dynamically.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 03:06 AM
- analyzed
- Aug 1, 2026, 03:08 AM
Related advisories
- nagixjs@2.1.6
- api-rust-sdk@2.1.6
- app-soda-layer@2.1.6
- vscode-designer-14@14.0.1
- messenger-style@1.0.1
- page-navigation@1.0.1
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.