LWA-2026-12367 confirmed malware

bunny-stream-react-native@1.0.0

Malicious code in bunny-stream-react-native (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Empty package (package.json only, no executable code) published under the name bunny-stream-react-native, which mimics a plausible react-native streaming library. The package ships no code, no install hooks, and no scripts beyond a placeholder test — a name-reservation / namespace-claim publish with no functional content. No network or file IOCs are present because no payload is shipped in this version.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 05:09 PM
analyzed
Sep 23, 2026, 05:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.