LWA-2026-12062 confirmed malware

@reause/rxjs@0.1.2

Malicious code in @reause/rxjs (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@reause/rxjs is a combosquat of the legitimate @vueuse/rxjs library, published under a near-identical scoped name. The package ships a React port of VueUse's rxjs utilities (toObserver, useObservable, useFrom, useSubject, useSubscription, useWatchExtractedObservable) with a dependency on @reause/shared, also a VueUse port. The shipped code contains no lifecycle hooks and no network activity; the risk is the combosquat name impersonating the well-known @vueuse/rxjs package to attract installers.

analyzed by
Leitwacht
first seen
Sep 11, 2026, 05:41 PM
analyzed
Sep 11, 2026, 05:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.