LWA-2026-4951 confirmed malware

react-remove-properties@6.14.0

Malicious code in react-remove-properties (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

A dependency-confusion package. The manifest declares a self-referencing dependency to hxxp://pack[.]nppacks[.]com/npm/react-remove-properties, an external HTTP URL instead of the npm registry, so npm install fetches and executes code from that external server during dependency resolution. It also depends on "axios", which likely resolves through the same external path. The shipped index.js is a bare 106-byte stub that only prints "Hello, world!" and carries an unverifiable "security testing PoC" claim with no repository URL or bug-bounty reference; the real payload is delivered from pack[.]nppacks[.]com at install time.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 12:53 AM
analyzed
Jun 13, 2026, 12:53 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.