qr-code-styling-temp@9.9.10
Malicious code in qr-code-styling-temp (npm)
Analysis
Same package (qr-code-styling-temp@9.9.10) as LWA-2026-4820, confirmed malware. Install hook loads obfuscated DNS beacon that collects username, hostname, and cwd, then exfiltrates them via dns.resolve4 queries to oob[.]sl4x0[.]xyz — an OOB DNS exfiltration channel during npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 05:53 PM
- analyzed
- Jun 12, 2026, 05:54 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.