MAL-2026-12337
Malicious code in akamaijs-sensor (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (14a4955c82b04226b267bc55691b0b9c08770710a7038b58e75bfdd009d046fe) The package presents itself as an Akamai sensor generator but ships two coupled malicious mechanisms. index.js contains a /* */ comment filled with invisible Unicode variation-selector characters (U+FE00-FE0F and U+E0100-E01EF) that encode arbitrary JavaScript bytes. sync-metrics.js reads that comment, decodes the hidden bytes via an unpack() routine mapping the variation-selector ranges to nibbles, and executes the resulting source through new Function('require', batch)(require) — running attacker-authored code inside the consumer's Node process the first time the exported sensor() API is called. Separately, index.js fetches a hardcoded personal Google Calendar ICS feed at calendar.google.com/calendar/ical/hev4229%40gmail.com/public/basic.ics, extracts a URL from event DESCRIPTION fields (accepting plain, base64-decoded, or HTML href forms), appends /generate, GETs that endpoint and returns its JSON to sensor()'s caller. The calendar functions as a dead-drop the operator rotates by editing calendar events, defeating static URL indicators and letting the operator swap the live endpoint at will. The combination — invisible-Unicode-encoded code executed via new Function() plus an attacker-rotatable C2 channel whose responses flow back through the package's advertised API — is remote code execution against the installer with no legitimate purpose in a sensor generator.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for akamaijs-sensor (npm). Pin to a known-safe version or switch to an alternative.