LWA-2026-3899 MAL-2026-5520 ↗ confirmed malware

@access-risk/browser-remedy-react@99.0.0

Malicious code in @access-risk/browser-remedy-react (npm)

Analysis

@access-risk/browser-remedy-react@99.0.0 is a 1.8KB dependency-confusion stub (3 files) that runs postinstall.js on install. The script collects system metadata (os.hostname(), os.userInfo().username, install path, and a directory tree to depth 2) and exfiltrates via two channels: an HTTPS POST of the base64-encoded JSON payload to the callback domain xjaipnfhcpawuhzlgzkzx9k5rrgo6df89.oast[.]fun, and a DNS fallback that encodes hostname and username as a hex subdomain label resolved against the same oast[.]fun domain. The exfiltration was observed carrying a JSON body of the form {"h":...,"u":"<user>","p":"...","tree":[...]}.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 10:58 AM
analyzed
Jun 10, 2026, 11:20 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.