LWA-2026-12367 confirmed malware
bunny-stream-react-native@1.0.0
Malicious code in bunny-stream-react-native (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Empty package (package.json only, no executable code) published under the name bunny-stream-react-native, which mimics a plausible react-native streaming library. The package ships no code, no install hooks, and no scripts beyond a placeholder test — a name-reservation / namespace-claim publish with no functional content. No network or file IOCs are present because no payload is shipped in this version.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 05:09 PM
- analyzed
- Sep 23, 2026, 05:11 PM
Related advisories
- tostpro@99.99.99
- event-hunter@1.0.0
- amoncasino@1.0.0
- casino-instant@1.0.0
- felix-spin@1.0.0
- roobet@1.0.0
- spinsy-casino@1.0.0
- casinolabcasino@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.