LWA-2026-5010 confirmed malware

reseller-app@9.9.11

Malicious code in reseller-app (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

An install hook (node index.js) silently loads an obfuscated payload that collects the system username, hostname, and current working directory name via os.userInfo(), os.hostname(), and process.cwd(). This data is exfiltrated via a DNS resolution query to the C2 domain oob[.]sl4x0[.]xyz in the format boltres.{user}.{host}.{cwd}.{timestamp}.oob[.]sl4x0[.]xyz. The package presents itself as enterprise utility code but the core payload is obfuscated using the javascript-obfuscator dictionary-array pattern and has no legitimate function.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 05:53 AM
analyzed
Jun 13, 2026, 05:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.