npm · Malicious package advisory
Malware@ceeferenderer/itg-renderer-sdk
MAL-2026-2407
Malicious code in @ceeferenderer/itg-renderer-sdk (npm)
Details
Malicious package due to code obfuscation, dynamic module loading, process exposure, suspicious install script, and untrustworthy author email.
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (51b9fa22264e38705c3a7ba319515ee66036e72ab14c32d08b01a5695aa191b8)
This package performs silent reconnaissance against any machine that installs or requires it. The package.json declares `scripts.install = node index.js`, and index.js also loads lib/core.js at require() time. lib/core.js obtains the `os` and `dns` modules via `module.constructor._load(...)` — a deliberate bypass of simple `require('os')`/`require('dns')` source grep — then reads `os.userInfo().username`, `os.hostname()`, and `path.basename(process.cwd())`, concatenates them with a timestamp and the hard-coded domain `oob.sl4x0.xyz`, and calls `dns.resolve4()` on the resulting subdomain. Because `oob.sl4x0.xyz` is an attacker-controlled authoritative nameserver, the victim's resolver leaks the username, hostname, and working-directory name as DNS query labels. The sensitive identifiers and the domain itself are stored as hex byte arrays in lib/6ad264.js and lib/b02e30.js and reassembled at runtime via `String.fromCharCode`, and the JS filenames are random hex — clear evasion of static review. Supporting red flags: the author email is `research@sl4x0.xyz` (same attacker-owned domain), the version is `99.9.9`, and the package description is generic. This is active exfiltration of installer-side data executed on both install and import, with no legitimate functionality documented.
Compromised versions (1)
- 99.9.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.