OpenSSF/OSV advisory MAL-2026-12337 confirms this npm version as malicious. The package presents itself as an Akamai sensor generator but ships two coupled malicious mechanisms. index.js contains a /* */ comment filled with invisible Unicode variation-selector characters (U+FE00-FE0F and U+E0100-E01EF) that encode arbitrary JavaScript bytes. sync-metrics.js reads that comment, decodes the hidden bytes via an unpack() routine mapping the variation-selector ranges to nibbles, and executes the...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in akamaijs-sensor (npm)
Details
The package presents itself as an Akamai sensor generator but ships two coupled malicious mechanisms. index.js contains a /* */ comment filled with invisible Unicode variation-selector characters (U+FE00-FE0F and U+E0100-E01EF) that encode arbitrary JavaScript bytes. sync-metrics.js reads that comment, decodes the hidden bytes via an unpack() routine mapping the variation-selector ranges to nibbles, and executes the resulting source through new Function('require', batch)(require) — running attacker-authored code inside the consumer's Node process the first time the exported sensor() API is called. Separately, index.js fetches a hardcoded personal Google Calendar ICS feed at calendar.google.com/calendar/ical/hev4229%40gmail.com/public/basic.ics, extracts a URL from event DESCRIPTION fields (accepting plain, base64-decoded, or HTML href forms), appends /generate, GETs that endpoint and returns its JSON to sensor()'s caller. The calendar functions as a dead-drop the operator rotates by editing calendar events, defeating static URL indicators and letting the operator swap the live endpoint at will. The combination — invisible-Unicode-encoded code executed via new Function() plus an attacker-rotatable C2 channel whose responses flow back through the package's advertised API — is remote code execution against the installer with no legitimate purpose in a sensor generator.
Decision reason
OpenSSF Malicious Packages via OSV confirms akamaijs-sensor@2.0.0 as malicious (MAL-2026-12337): Malicious code in akamaijs-sensor (npm)