@reaxuse/core@0.0.1
Malicious code in @reaxuse/core (npm)
Analysis
@reaxuse/core@0.0.1 is a React hooks library presented as a port of the well-known @vueuse/core library. The published artifact is non-functional: it declares a dependency on a sibling package via a file: protocol path ("@reaxuse/shared": "file:../shared") that cannot resolve from the npm registry, so installing it yields a broken package. The package ships a large compiled bundle of React hooks (useFetch, useWebSocket, useStorage, etc.) with no install-time lifecycle hook and no executable payload in this version. The non-resolving file: dependency and the name similarity to a legitimate library are consistent with a placeholder/decoy package shape; no network exfiltration or credential access is present in this version.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:42 AM
- analyzed
- Sep 10, 2026, 04:43 AM
Related advisories
- @reaxuse/integrations@0.0.1
- @reaxuse/firebase@0.0.1
- @reaxuse/shared@0.0.1
- @reaxuse/rxjs@0.0.1
- @reaxuse/router@0.0.1
- etoro-aggregator@999.0.0
- etoro-cashout@999.0.0
- etoro-builders@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.