LWA-2026-11986 confirmed malware

@reaxuse/router@0.0.1

Malicious code in @reaxuse/router (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reaxuse/router@0.0.1 is a namespace-squat placeholder published under the reaxuse name (a React port of the @vueuse/router library). The package claims to provide router bindings but ships an empty stub: the sole source file has all exports commented out and contains only `export {}`, and the built dist/index.js is 0 bytes. No functional code, no dependencies, and no install hooks are present — the package exists only to occupy the @reaxuse/router name. Analysis is metadata-based; no network IOCs or executable payload were present in the tarball.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:42 AM
analyzed
Sep 10, 2026, 04:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.