LWA-2026-4548 confirmed malware

paypal-examples-openai@99.99.9

Malicious code in paypal-examples-openai (npm)

T1059.007 · JavaScriptT1071.004 · DNS

Analysis

paypal-examples-openai@99.99.9 is a combosquat impersonating both the PayPal and OpenAI brands at sentinel version 99.99.9. The 198-byte tarball contains only a package.json whose postinstall script runs a DNS lookup to r6dw6gvi43cpc4piugll167rg[.]canarytokens[.]com, beaconing the installer's IP address. It has no README, license, repository URL, or stated research purpose. The beaconing stub is a namespace-claim pattern: reserve the combosquat name, phone home on install, then ship a real payload in later versions.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 02:45 AM
analyzed
Jun 12, 2026, 02:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.