LWA-2026-4820 MAL-2026-4655 ↗ confirmed malware

qr-code-styling-temp@9.9.10

Malicious code in qr-code-styling-temp (npm)

Analysis

Same package (qr-code-styling-temp@9.9.10) as LWA-2026-4820, confirmed malware. Install hook loads obfuscated DNS beacon that collects username, hostname, and cwd, then exfiltrates them via dns.resolve4 queries to oob[.]sl4x0[.]xyz — an OOB DNS exfiltration channel during npm install.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 05:53 PM
analyzed
Jun 12, 2026, 05:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.