LWA-2026-11714 confirmed malware

dsh-tauri-rightclick@0.4.9

Malicious code in dsh-tauri-rightclick (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

dsh-tauri-rightclick@0.4.9 is an npm package published as a DeepSeek Harness desktop-wrapper plugin providing right-click context menus. The package ships a host-side HTTP route (dist/index.js) that opens http/https URLs via the system default browser (rundll32/open/xdg-open) with same-origin JSON validation and an http/https-only URL whitelist, and a browser-side context-menu module (dist/client.js) handling clipboard operations, DOM element location, and host RPC calls to /api/host.openPath and /api/dsh-rightclick-menu/open-url. No install lifecycle scripts, no binary downloads, and no outbound network exfiltration were observed in the shipped code.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 06:25 AM
analyzed
Aug 29, 2026, 06:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.