VDB

MAL-2026-16290

MAL-2026-16290 PUBLISHED CVSS 9.300000190734863 CRITICAL

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a659995af42be0d4f8360b45a37295eab4d68f513c6b3aa49903b3028e0567f5) The package's `install` lifecycle script runs `node index.js`, which loads `lib/core.js`. On install, that module collects `os.userInfo().username`, `os.hostname()`, and the basename of the current working directory, then issues a `dns.resolve4` for a subdomain composed of those values under the hardcoded external domain `oob.algamil7x.xyz`. Module loads and the destination hostname are hex-array obfuscated: `lib/g7h8i9.js` uses `module.constructor._load` with hex-decoded strings to require `os`, `dns`, and `process`, and `lib/h8i9j0.js` stores the destination as hex arrays that decode to `oob.algamil7x.xyz`. The package name typosquats a legitimate ad-tech scope, and no functionality matching that stated purpose is present — the install-time DNS beacon is the package's only observable behavior.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
insiderintelligencegoogleadmanager
insiderintelligencegoogleadmanager9.9.10

Timeline

  • Sep 18, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›