LWA-2026-4927 confirmed malware

react-emits@1.0.5

Malicious code in react-emits (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

react-emits@1.0.5 is a combosquat package masquerading as a Node.js path utility. Its postinstall hook runs path.js, which bundles Node's path module as cover but embeds two base64-encoded URLs (decoding to hxxp://173[.]211[.]46[.]220/lverla[.]js and /lverl). Two IIFEs at the bottom of the file fetch these URLs, parse the response as JSON, and eval() the .content field — a classic second-stage remote code execution loader. The package also depends on axios, a known-malware marked dependency. While no static token-theft markers were found in this version, the runtime payload fetched from the remote IP can execute arbitrary code on the installer's machine.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 09:40 PM
analyzed
Jun 12, 2026, 09:40 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.