CRITICAL npm Malware

Malicious code in @insiderintelligence/googleadmanager (npm)

MAL-2026-16290

Published · Modified

Dependency scanning

Check whether @insiderintelligence/googleadmanager is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (a659995af42be0d4f8360b45a37295eab4d68f513c6b3aa49903b3028e0567f5)

The package's install lifecycle script runs node index.js, which loads lib/core.js. On install, that module collects os.userInfo().username, os.hostname(), and the basename of the current working directory, then issues a dns.resolve4 for a subdomain composed of those values under the hardcoded external domain oob.algamil7x.xyz. Module loads and the destination hostname are hex-array obfuscated: lib/g7h8i9.js uses module.constructor._load with hex-decoded strings to require os, dns, and process, and lib/h8i9j0.js stores the destination as hex arrays that decode to oob.algamil7x.xyz. The package name typosquats a legitimate ad-tech scope, and no functionality matching that stated purpose is present — the install-time DNS beacon is the package's only observable behavior.

Ready to move

Start Securing

Free, no credit card | First findings in minutes