VYPR

npm · Malicious package advisory

Malware

bolt-delivery-menu-app

GHSA-75c2-fw59-mg5f

Malicious code in bolt-delivery-menu-app (npm)

Details

**Severity:** Critical

**Affected versions:** `= 9.9.11`

## Source: amazon-inspector (cc39247db76b4edd80084e400324518739f141dafda621d368c3e5a9ac41f791)
Package executes a DNS-based beacon at both install time (package.json scripts.install runs `node index.js`) and on every `require()` of the module. lib/core.js reads `os.userInfo().username`, `os.hostname()`, and `process.cwd()`, concatenates them with a campaign tag into a single label, and triggers `dns.resolve4` against that label under the attacker-controlled domain `oob.sl4x0.xyz`, leaking installer host identity over DNS (a channel chosen to bypass HTTP-egress controls). The C2 domain and Node built-in names (`os`, `dns`, `process`, `resolve4`) are stored as char-code arrays in lib/b02e30.js and lib/6ad264.js to defeat string-grep scanners. The package name `bolt-delivery-menu-app` impersonates the Bolt delivery brand while shipping generic 'Enterprise Utilities' boilerplate as its cover story, and the author email `[email protected]` resolves to the same domain as the exfil destination — the typosquat lure, the cover identity, and the C2 are one operation. README falsely claims 'No network requests'.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/924e3cfb512a9097299503a28807f7cbe55b2975/osv/malicious/npm/bolt-delivery-menu-app/MAL-2026-4499.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/924e3cfb512a9097299503a28807f7cbe55b2975/osv/malicious/npm/bolt-delivery-menu-app/MAL-2026-4499.json
- https://www.npmjs.com/package/bolt-delivery-menu-app/v/9.9.11
- https://github.com/advisories/GHSA-75c2-fw59-mg5f

Compromised versions (1)

  • = 9.9.11

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.