Malicious code in @insiderintelligence/googleadmanager (npm)
MAL-2026-16290
Published · Modified
Dependency scanning
Check whether @insiderintelligence/googleadmanager is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (a659995af42be0d4f8360b45a37295eab4d68f513c6b3aa49903b3028e0567f5)
The package's install lifecycle script runs node index.js, which loads lib/core.js. On install, that module collects os.userInfo().username, os.hostname(), and the basename of the current working directory, then issues a dns.resolve4 for a subdomain composed of those values under the hardcoded external domain oob.algamil7x.xyz. Module loads and the destination hostname are hex-array obfuscated: lib/g7h8i9.js uses module.constructor._load with hex-decoded strings to require os, dns, and process, and lib/h8i9j0.js stores the destination as hex arrays that decode to oob.algamil7x.xyz. The package name typosquats a legitimate ad-tech scope, and no functionality matching that stated purpose is present — the install-time DNS beacon is the package's only observable behavior.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes