LWA-2026-11986 confirmed malware
@reaxuse/router@0.0.1
Malicious code in @reaxuse/router (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@reaxuse/router@0.0.1 is a namespace-squat placeholder published under the reaxuse name (a React port of the @vueuse/router library). The package claims to provide router bindings but ships an empty stub: the sole source file has all exports commented out and contains only `export {}`, and the built dist/index.js is 0 bytes. No functional code, no dependencies, and no install hooks are present — the package exists only to occupy the @reaxuse/router name. Analysis is metadata-based; no network IOCs or executable payload were present in the tarball.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:42 AM
- analyzed
- Sep 10, 2026, 04:43 AM
Related advisories
- @reaxuse/integrations@0.0.1
- @reaxuse/firebase@0.0.1
- @reaxuse/core@0.0.1
- etoro-aggregator@999.0.0
- etoro-cashout@999.0.0
- etoro-builders@999.0.0
- etoro-billing@999.0.0
- etoro-api@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.