LWA-2026-4548 confirmed malware
paypal-examples-openai@99.99.9
Malicious code in paypal-examples-openai (npm)
T1059.007 · JavaScriptT1071.004 · DNS
Analysis
paypal-examples-openai@99.99.9 is a combosquat impersonating both the PayPal and OpenAI brands at sentinel version 99.99.9. The 198-byte tarball contains only a package.json whose postinstall script runs a DNS lookup to r6dw6gvi43cpc4piugll167rg[.]canarytokens[.]com, beaconing the installer's IP address. It has no README, license, repository URL, or stated research purpose. The beaconing stub is a namespace-claim pattern: reserve the combosquat name, phone home on install, then ship a real payload in later versions.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 02:45 AM
- analyzed
- Jun 12, 2026, 02:46 AM
Related advisories
- paasprint-sdk@9.9.9
- oc-navbar-module-client@9.9.10
- @whatnot-web/www-legacy@99.1.2
- mermaid-v11@9999.0.0
- mimecast-web-components@2.0.0
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.