Logo
npm

bolt-delivery-menu-app@9.9.11

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 12:33 PM UTC

Malicious

OSV ID

MAL-2026-4499

Ecosystem

npm

Summary

Package executes a DNS-based beacon at both install time (package.json scripts.install runs node index.js) and on every require() of the module. lib/core.js reads os.userInfo().username, os.hostname(), and process.cwd(), concatenates them with a campaign tag into a single label, and triggers dns.resolve4 against that label under the attacker-controlled domain oob.sl4x0.xyz, leaking installer host identity over DNS (a channel chosen to bypass HTTP-egress controls). The C2 domain and Node built-in names (os, dns, process, resolve4) are stored as char-code arrays in lib/b02e30.js and lib/6ad264.js to defeat string-grep scanners. The package name bolt-delivery-menu-app impersonates the Bolt delivery brand while shipping generic 'Enterprise Utilities' boilerplate as its cover story, and the author email research@sl4x0.xyz resolves to the same domain as the exfil destination — the typosquat lure, the cover identity, and the C2 are one operation. README falsely claims 'No network requests'.

Source: amazon-inspector (cc39247db76b4edd80084e400324518739f141dafda621d368c3e5a9ac41f791)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.