LWA-2026-12046 confirmed malware

@reause/electron@0.1.2

Malicious code in @reause/electron (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reause/electron is a typosquat of the legitimate @vueuse/electron package (name "reause" vs "vueuse"), published under the @reause/* scoped namespace together with a sibling dependency @reause/shared. The package impersonates the VueUse electron renderer hooks library. Installers who intended to depend on @vueuse/electron may pull this package instead. The bundled code is a React port of VueUse hooks with no detectable executable payload in this version.

analyzed by
Leitwacht
first seen
Sep 11, 2026, 05:41 PM
analyzed
Sep 11, 2026, 05:42 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.