qr-code-styling-temp@9.9.10
Malicious code in qr-code-styling-temp (npm)
Analysis
Same package (qr-code-styling-temp@9.9.10) as LWA-2026-4820, confirmed malware. Install hook loads obfuscated DNS beacon that collects username, hostname, and cwd, then exfiltrates them via dns.resolve4 queries to oob[.]sl4x0[.]xyz — an OOB DNS exfiltration channel during npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 05:53 PM
- analyzed
- Jun 12, 2026, 05:54 PM
Related advisories
- atlassian-forge-skills@29.1.0
- poloman@9.2.1
- paypal-examples-openai@99.99.9
- paasprint-sdk@9.9.9
- oc-navbar-module-client@9.9.10
- @whatnot-web/www-legacy@99.1.2
- mermaid-v11@9999.0.0
- mimecast-web-components@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.