@reaxuse/shared@0.0.1
Malicious code in @reaxuse/shared (npm)
Analysis
@reaxuse/shared@0.0.1 is a React utility library published under a name resembling the legitimate @vueuse/shared package. This first version ships a set of React composables (createEventHook, createGlobalState, useDebounceFn, useThrottleFn, etc.) with no install-time lifecycle hooks and no network behaviour. The package name is a variant of the well-known @vueuse/shared package, and this appears to be a trust-establishing first release from a publisher whose prior packages have been confirmed malicious; treat the package and any subsequent versions as untrusted.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 04:42 AM
- analyzed
- Sep 10, 2026, 04:43 AM
Related advisories
- @reaxuse/integrations@0.0.1
- @reaxuse/firebase@0.0.1
- @reaxuse/core@0.0.1
- @reaxuse/rxjs@0.0.1
- @reaxuse/router@0.0.1
- etoro-aggregator@999.0.0
- etoro-cashout@999.0.0
- etoro-builders@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.