MAL-2026-14066

    Dashboard / Malicious Package / MAL-2026-14066

    MAL-2026-14066

    Published: 15 Aug 2026Last Modified: 15 Aug 2026

    Summary: Malicious code in akamaijs-sensorv1 (npm)

    Details: Source: amazon-inspector (9524ba80283c25fe34b7a9630fc0f65ac8cf112e33a50aa4cbaac19239fcc267) The package advertises itself as an Akamai Bot Manager sensor generator, but its main entry conceals its real behavior. index.js contains a comment composed of invisible Unicode tag / variation-selector code points (U+FE00-U+FE0F and U+E0100-U+E01EF). sync-metrics.js reads the package's own index.js, decodes those invisible characters back into bytes, and executes the resulting string via new Function('require', batch)(require) — a hidden dynamic-eval sink that runs whenever a consumer invokes the exported sensor() API. sensor() additionally fetches a hardcoded public Google Calendar ICS feed (calendar.google.com/calendar/ical/hev4229%40gmail.com/public/basic.ics), parses the newest event's DESCRIPTION field for a URL (accepting plain text, href, or base64-encoded forms), rewrites it to end in /generate, issues a GET to that URL, and returns the response as JSON to the caller. The network destination the installer's process contacts is therefore controlled by whoever owns the [email protected] calendar and can be changed at any time by editing a calendar event, with no pinning, signing, or authentication of the retrieved URL. The invisible-character steganography, hidden eval, calendar-based dead-drop C2, and Akamai-lure package name together form a covert remote-code / attacker-controlled-redirector channel.

    Affected packages

    Package

    Name: akamaijs-sensorv1

    Purl: pkg:npm/akamaijs-sensorv1

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.0.0
    MAL-2026-14066 | CVE-DB