LWA-2026-12071 confirmed malware
@reause/math@0.1.2
Malicious code in @reause/math (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@reause/math@0.1.2 is a React math utility library that re-exports VueUse math functions (useAbs, useCeil, useClamp, useProjection, logicAnd/Or/Not, useSum, useMax, useMin, usePrecision, useRound, useTrunc, useMath, createProjection, createGenericProjection). The shipped dist/index.js and dist/index.iife.js contain only pure arithmetic functions with no network access, no subprocess execution, and no lifecycle hooks. The package depends on @reause/shared@0.1.2. No malicious runtime behaviour is present in the published code.
- analyzed by
- Leitwacht
- first seen
- Sep 11, 2026, 05:41 PM
- analyzed
- Sep 11, 2026, 05:42 PM
Related advisories
- @reause/rxjs@0.1.2
- @reause/electron@0.1.2
- tailwindcss-contact-forms@0.5.8
- billion-context-dsh-patch@0.2.21-patch.1
- @reaxuse/integrations@0.0.1
- @reaxuse/firebase@0.0.1
- @reaxuse/core@0.0.1
- @reaxuse/shared@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.