LWA-2026-11420 confirmed malware
react-dom-helpers@3.3.3
Malicious code in react-dom-helpers (npm)
T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
react-dom-helpers@3.3.3 is a trojanized clone of the react-dom package. Its ./client entry point (client.js) runs a recon beacon on require: it enumerates the machine's local IPv4 addresses via os.networkInterfaces(), fetches the public IP from api[.]ipify[.]org, and POSTs the collected IP information to a Slack channel via slack[.]com/api/chat.postMessage using a hardcoded Slack bot token. The package exfiltrates host network metadata to an external Slack channel.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 05:27 PM
- analyzed
- Aug 18, 2026, 05:27 PM
Related advisories
- bqq1@1.0.0
- @library-dev-team/data-sanitizer@1.3.0
- @oyo_tech/oyochat_user@100.0.0
- optimizely-starter-kit-for-fastly-compute@1.0.1
- prism-registry@1.0.1
- fast-glob-fast@8.0.0
- space-items@1.0.0
- leb128x@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.