@ceeferenderer/itg-renderer-sdk@99.9.9
Vulnerability report · Last retrieved from osv.dev September 7, 2026 at 6:03 PM UTC
OSV ID
MAL-2026-2407
Ecosystem
npm
Summary
This package performs silent reconnaissance against any machine that installs or requires it. The package.json declares scripts.install = node index.js, and index.js also loads lib/core.js at require() time. lib/core.js obtains the os and dns modules via module.constructor._load(...) — a deliberate bypass of simple require('os')/require('dns') source grep — then reads os.userInfo().username, os.hostname(), and path.basename(process.cwd()), concatenates them with a timestamp and the hard-coded domain oob.sl4x0.xyz, and calls dns.resolve4() on the resulting subdomain. Because oob.sl4x0.xyz is an attacker-controlled authoritative nameserver, the victim's resolver leaks the username, hostname, and working-directory name as DNS query labels. The sensitive identifiers and the domain itself are stored as hex byte arrays in lib/6ad264.js and lib/b02e30.js and reassembled at runtime via String.fromCharCode, and the JS filenames are random hex — clear evasion of static review. Supporting red flags: the author email is research@sl4x0.xyz (same attacker-owned domain), the version is 99.9.9, and the package description is generic. This is active exfiltration of installer-side data executed on both install and import, with no legitimate functionality documented.
Source: amazon-inspector (51b9fa22264e38705c3a7ba319515ee66036e72ab14c32d08b01a5695aa191b8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.