LWA-2026-11987 confirmed malware

@reaxuse/rxjs@0.0.1

Malicious code in @reaxuse/rxjs (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reaxuse/rxjs is a scoped-name package that mirrors the vueuse/rxjs library name (a React port of the RxJS reactive utilities). This version ships only benign React hook code (toObserver and useWatchExtractedObservable) with no detectable malicious payload, no lifecycle hooks, and no network activity. It is published as part of a broader pattern of scoped-name packages impersonating established reactive-programming libraries.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:42 AM
analyzed
Sep 10, 2026, 04:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.