LWA-2026-11988 confirmed malware

@reaxuse/shared@0.0.1

Malicious code in @reaxuse/shared (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reaxuse/shared@0.0.1 is a React utility library published under a name resembling the legitimate @vueuse/shared package. This first version ships a set of React composables (createEventHook, createGlobalState, useDebounceFn, useThrottleFn, etc.) with no install-time lifecycle hooks and no network behaviour. The package name is a variant of the well-known @vueuse/shared package, and this appears to be a trust-establishing first release from a publisher whose prior packages have been confirmed malicious; treat the package and any subsequent versions as untrusted.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 04:42 AM
analyzed
Sep 10, 2026, 04:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.