LWA-2026-11420 confirmed malware

react-dom-helpers@3.3.3

Malicious code in react-dom-helpers (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

react-dom-helpers@3.3.3 is a trojanized clone of the react-dom package. Its ./client entry point (client.js) runs a recon beacon on require: it enumerates the machine's local IPv4 addresses via os.networkInterfaces(), fetches the public IP from api[.]ipify[.]org, and POSTs the collected IP information to a Slack channel via slack[.]com/api/chat.postMessage using a hardcoded Slack bot token. The package exfiltrates host network metadata to an external Slack channel.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 05:27 PM
analyzed
Aug 18, 2026, 05:27 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.