react-native-international-phone-number@0.12.3
Malicious code in react-native-international-phone-number (npm)
Analysis
The package declares runtime dependencies on react-native-country-select@0.3.9 and @agnoliaarisian7180/string-argv — both are known malicious packages. The library code imports from react-native-country-select as its country-picker module, making the malware a transitive dependency that npm installs automatically. Versions 0.12.1 and 0.12.2 also declare a preinstall hook (node install.js) that points to a file absent from the published tarball. Version 0.12.3 removed the preinstall hook but retains both malicious dependencies, widening @agnoliaarisian7180/string-argv to 'latest' to always pull the newest version. The publisher email ([account]) is also the maintainer of the malicious react-native-country-select package. Installing this package triggers automatic download and execution of the malicious dependency chain via npm's lifecycle hooks.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 12:08 AM
- analyzed
- Jun 13, 2026, 12:10 AM
Related advisories
- react-native-international-phone-number@0.12.2 same package
- react-native-international-phone-number@0.12.1 same package
- warp-dependency@1.0.0
- react-emits@1.0.5
- rc-icon@99.9.1
- theta-connector@1.0.0
- chalk-pro@7.0.4
- richtext-editor-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.