npm · Malicious package advisory
Malwarebolt-delivery-menu-app
GHSA-75c2-fw59-mg5f
Malicious code in bolt-delivery-menu-app (npm)
Details
**Severity:** Critical **Affected versions:** `= 9.9.11` ## Source: amazon-inspector (cc39247db76b4edd80084e400324518739f141dafda621d368c3e5a9ac41f791) Package executes a DNS-based beacon at both install time (package.json scripts.install runs `node index.js`) and on every `require()` of the module. lib/core.js reads `os.userInfo().username`, `os.hostname()`, and `process.cwd()`, concatenates them with a campaign tag into a single label, and triggers `dns.resolve4` against that label under the attacker-controlled domain `oob.sl4x0.xyz`, leaking installer host identity over DNS (a channel chosen to bypass HTTP-egress controls). The C2 domain and Node built-in names (`os`, `dns`, `process`, `resolve4`) are stored as char-code arrays in lib/b02e30.js and lib/6ad264.js to defeat string-grep scanners. The package name `bolt-delivery-menu-app` impersonates the Bolt delivery brand while shipping generic 'Enterprise Utilities' boilerplate as its cover story, and the author email `[email protected]` resolves to the same domain as the exfil destination — the typosquat lure, the cover identity, and the C2 are one operation. README falsely claims 'No network requests'. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/924e3cfb512a9097299503a28807f7cbe55b2975/osv/malicious/npm/bolt-delivery-menu-app/MAL-2026-4499.json)) **References:** - https://github.com/ossf/malicious-packages/blob/924e3cfb512a9097299503a28807f7cbe55b2975/osv/malicious/npm/bolt-delivery-menu-app/MAL-2026-4499.json - https://www.npmjs.com/package/bolt-delivery-menu-app/v/9.9.11 - https://github.com/advisories/GHSA-75c2-fw59-mg5f
Compromised versions (1)
- = 9.9.11
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.