malware npm

gs-uitk-testing-utils

discovered 2026-07-23

Dependency-confusion package squatting Goldman Sachs' internal gs-uitk-* UI-toolkit namespace. Publisher [email protected]; author identity [email protected] (reused from the campaign's Anduril-targeting PyPI cluster). install lifecycle hook runs node index.js unconditionally, loading a hex-array-obfuscated loader (lib/6ad264.js) that reaches os/dns via module.constructor._load() plus String.fromCharCode indirection, harvests username/hostname/cwd, and exfiltrates via dns.resolve4() to oob.sl4x0.xyz with per-package DNS tag goldman2. index.js and lib/6ad264.js are SHA256-identical to gs-uitk-object-utils (hash values not available). Part of the sl4x0 Enterprise Dependency Confusion campaign.

Threat types

dependency_confusion data_exfiltration

Malicious versions

  • 9.9.11

Campaigns

Indicators

Techniques

Read the full analysis →