dsh-tauri-rightclick@0.4.9
Malicious code in dsh-tauri-rightclick (npm)
Analysis
dsh-tauri-rightclick@0.4.9 is an npm package published as a DeepSeek Harness desktop-wrapper plugin providing right-click context menus. The package ships a host-side HTTP route (dist/index.js) that opens http/https URLs via the system default browser (rundll32/open/xdg-open) with same-origin JSON validation and an http/https-only URL whitelist, and a browser-side context-menu module (dist/client.js) handling clipboard operations, DOM element location, and host RPC calls to /api/host.openPath and /api/dsh-rightclick-menu/open-url. No install lifecycle scripts, no binary downloads, and no outbound network exfiltration were observed in the shipped code.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 06:25 AM
- analyzed
- Aug 29, 2026, 06:25 AM
Related advisories
- nx-app@9999.0.0-security-test
- @berrysdk/transport@0.1.9
- @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be
- cacao1@9.9.9
- melbet-ivoire@1.0.0
- @bx-ui-framework/common@15.0.0
- manager-thedate@1.0.16
- vitest-chalk-pro@10.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.