LWA-2026-11985 confirmed malware

@reaxuse/core@0.0.1

Malicious code in @reaxuse/core (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reaxuse/core@0.0.1 is a React hooks library presented as a port of the well-known @vueuse/core library. The published artifact is non-functional: it declares a dependency on a sibling package via a file: protocol path ("@reaxuse/shared": "file:../shared") that cannot resolve from the npm registry, so installing it yields a broken package. The package ships a large compiled bundle of React hooks (useFetch, useWebSocket, useStorage, etc.) with no install-time lifecycle hook and no executable payload in this version. The non-resolving file: dependency and the name similarity to a legitimate library are consistent with a placeholder/decoy package shape; no network exfiltration or credential access is present in this version.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:42 AM
analyzed
Sep 10, 2026, 04:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.