LWA-2026-11983 confirmed malware

@reaxuse/firebase@0.0.1

Malicious code in @reaxuse/firebase (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reaxuse/firebase@0.0.1 is a combosquat of the Firebase package: the real firebase name is used intact under the @reaxuse/ scope. The package ships a single version with no repository, no readme, and no source documentation, and its tarball is no longer retrievable from the registry, so the payload cannot be inspected. It is a firebase-impersonating package with no verifiable provenance.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:42 AM
analyzed
Sep 10, 2026, 04:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.