LWA-2026-11422 confirmed malware

plugin-react-vite@2.1.2

Malicious code in plugin-react-vite (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

plugin-react-vite@2.1.2 is a remote-code-execution dropper. Its main entry point (index.js) fetches a payload from hxxp://31[.]97[.]137[.]157:45000/icons/116 (raw IP, non-standard port, custom header "bearrtoken: logo") and executes the response's `credits` field via the Function constructor with full Node.js context (require, process, Buffer, module), so the actual malicious code is served remotely and never shipped in the package. The package name impersonates the Vite React plugin ecosystem and its README is a mismatched copy-paste from an unrelated package. C2: 31[.]97[.]137[.]157:45000, path /icons/116.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 05:32 PM
analyzed
Aug 18, 2026, 05:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.