LWA-2026-11983 confirmed malware
@reaxuse/firebase@0.0.1
Malicious code in @reaxuse/firebase (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@reaxuse/firebase@0.0.1 is a combosquat of the Firebase package: the real firebase name is used intact under the @reaxuse/ scope. The package ships a single version with no repository, no readme, and no source documentation, and its tarball is no longer retrievable from the registry, so the payload cannot be inspected. It is a firebase-impersonating package with no verifiable provenance.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:42 AM
- analyzed
- Sep 10, 2026, 04:45 AM
Related advisories
- @reaxuse/integrations@0.0.1
- @reaxuse/core@0.0.1
- @reaxuse/shared@0.0.1
- @reaxuse/rxjs@0.0.1
- @reaxuse/router@0.0.1
- etoro-aggregator@999.0.0
- etoro-cashout@999.0.0
- etoro-builders@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.