LWA-2026-4946 confirmed malware
react-native-wcandillon@4.1.0
Malicious code in react-native-wcandillon (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The manifest declares a self-dependency to the external HTTP URL hxxp://pack[.]nppacks[.]com/npm/react-native-wcandillon in both dependencies and devDependencies. On install, the dependency resolver fetches a tarball from that unencrypted, attacker-controlled host, allowing arbitrary code delivery at installation time. The bundled index.js is a trivial 106-byte "Hello, world!" stub; the threat is the redirector manifest. An inline "security testing PoC" comment is unverifiable (no repository URL, bug-bounty program, or published research).
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 12:23 AM
- analyzed
- Jun 13, 2026, 12:24 AM
Related advisories
- react-native-international-phone-number@0.12.3
- react-native-international-phone-number@0.12.1
- warp-dependency@1.0.0
- react-emits@1.0.5
- rc-icon@99.9.1
- theta-connector@1.0.0
- chalk-pro@7.0.4
- richtext-editor-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.