LWA-2026-11987 confirmed malware
@reaxuse/rxjs@0.0.1
Malicious code in @reaxuse/rxjs (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@reaxuse/rxjs is a scoped-name package that mirrors the vueuse/rxjs library name (a React port of the RxJS reactive utilities). This version ships only benign React hook code (toObserver and useWatchExtractedObservable) with no detectable malicious payload, no lifecycle hooks, and no network activity. It is published as part of a broader pattern of scoped-name packages impersonating established reactive-programming libraries.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:42 AM
- analyzed
- Sep 10, 2026, 04:43 AM
Related advisories
- @reaxuse/integrations@0.0.1
- @reaxuse/firebase@0.0.1
- @reaxuse/core@0.0.1
- @reaxuse/router@0.0.1
- etoro-aggregator@999.0.0
- etoro-cashout@999.0.0
- etoro-builders@999.0.0
- etoro-billing@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.