LWA-2026-4946 confirmed malware

react-native-wcandillon@4.1.0

Malicious code in react-native-wcandillon (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The manifest declares a self-dependency to the external HTTP URL hxxp://pack[.]nppacks[.]com/npm/react-native-wcandillon in both dependencies and devDependencies. On install, the dependency resolver fetches a tarball from that unencrypted, attacker-controlled host, allowing arbitrary code delivery at installation time. The bundled index.js is a trivial 106-byte "Hello, world!" stub; the threat is the redirector manifest. An inline "security testing PoC" comment is unverifiable (no repository URL, bug-bounty program, or published research).

analyzed by
Leitwacht
first seen
Jun 13, 2026, 12:23 AM
analyzed
Jun 13, 2026, 12:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.