LWA-2026-4942 confirmed malware

react-native-international-phone-number@0.12.1

Malicious code in react-native-international-phone-number (npm)

Analysis

The package declares runtime dependencies on react-native-country-select@0.3.9 and @agnoliaarisian7180/string-argv — both are known malicious packages. The library code imports from react-native-country-select as its country-picker module, making the malware a transitive dependency that npm installs automatically. Versions 0.12.1 and 0.12.2 also declare a preinstall hook (node install.js) that points to a file absent from the published tarball. Version 0.12.3 removed the preinstall hook but retains both malicious dependencies, widening @agnoliaarisian7180/string-argv to 'latest' to always pull the newest version. The publisher email ([account]) is also the maintainer of the malicious react-native-country-select package. Installing this package triggers automatic download and execution of the malicious dependency chain via npm's lifecycle hooks.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 12:08 AM
analyzed
Jun 13, 2026, 12:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.