LWA-2026-5010 confirmed malware
reseller-app@9.9.11
Malicious code in reseller-app (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
An install hook (node index.js) silently loads an obfuscated payload that collects the system username, hostname, and current working directory name via os.userInfo(), os.hostname(), and process.cwd(). This data is exfiltrated via a DNS resolution query to the C2 domain oob[.]sl4x0[.]xyz in the format boltres.{user}.{host}.{cwd}.{timestamp}.oob[.]sl4x0[.]xyz. The package presents itself as enterprise utility code but the core payload is obfuscated using the javascript-obfuscator dictionary-array pattern and has no legitimate function.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 05:53 AM
- analyzed
- Jun 13, 2026, 05:55 AM
Related advisories
- rendezvous-js@9.9.11
- qr-code-styling-temp@9.9.10
- atlassian-forge-skills@29.1.0
- poloman@9.2.1
- paypal-examples-openai@99.99.9
- paasprint-sdk@9.9.9
- oc-navbar-module-client@9.9.10
- @whatnot-web/www-legacy@99.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.