react-emits@1.0.5
Malicious code in react-emits (npm)
Analysis
react-emits@1.0.5 is a combosquat package masquerading as a Node.js path utility. Its postinstall hook runs path.js, which bundles Node's path module as cover but embeds two base64-encoded URLs (decoding to hxxp://173[.]211[.]46[.]220/lverla[.]js and /lverl). Two IIFEs at the bottom of the file fetch these URLs, parse the response as JSON, and eval() the .content field — a classic second-stage remote code execution loader. The package also depends on axios, a known-malware marked dependency. While no static token-theft markers were found in this version, the runtime payload fetched from the remote IP can execute arbitrary code on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 09:40 PM
- analyzed
- Jun 12, 2026, 09:40 PM
Related advisories
- theta-connector@1.0.0
- chalk-pro@7.0.4
- richtext-editor-ui@1.0.0
- rapidsearch@1.1.0
- qbo-ui-services@45.0.0
- theta-kit@1.0.0
- prm-bundles@45.0.0
- poxios-chain@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.