toast-react-slider@1.0.0
Malicious code in toast-react-slider (npm)
Analysis
toast-react-slider@1.0.0 is a combosquat of the rc-slider React component. Its preinstall script runs an obfuscated JavaScript downloader (package/comin.js) that targets Windows systems. The downloader checks if os.type() returns 'Windows_NT', then uses curl to download a payload from a remote URL (constructed as hxxp://127[.]0[.]{address}/download[.]asp?token=2810) via exec(). After downloading, it verifies the file size against the server's reported size, executes the downloaded payload, and deletes it. The package also bundles a native Windows PE DLL at source/StartUpNode.dll (194560 bytes, internally named StartUpDll.dll) which imports CreateProcessW, SHGetFolderPathW, WriteFile, and CreateThread — capabilities consistent with file deployment and process execution. The legitimate rc-slider and rc-util source code is included as camouflage.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 04:32 AM
- analyzed
- Jun 15, 2026, 04:35 AM
Related advisories
- redirect-azlazy@1.0.0
- oit-lib-oracle-util@45.0.0
- no-date-parsing@2.2.0
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.