LWA-2026-11984 confirmed malware

@reaxuse/integrations@0.0.1

Malicious code in @reaxuse/integrations (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This package is a React port of the legitimate @vueuse/integrations library, published as part of a coordinated campaign that has distributed malware across many packages under the same publishing identity. The package ships clean React hooks (useAsyncValidator, useAxios, useChangeCase, useCookies, useSortable, useDrauu, useFocusTrap, useIDBKeyval, useNProgress, useFuse, useJwt, useQRCode) with no install hooks and no network behaviour of its own, but it is a clone of a well-known library published by an identity with a history of distributing malicious packages, consistent with a decoy or reputation-building package in a supply-chain attack campaign.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:42 AM
analyzed
Sep 10, 2026, 04:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.