LWA-2026-4955 confirmed malware
react-schedule-it@4.0.0
Malicious code in react-schedule-it (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
A downloader/loader. The manifest declares a dependency on itself at hxxp://pack[.]nppacks[.]com/npm/react-schedule-it (HTTP, not HTTPS), so npm install fetches a tarball from an untrusted, MITM-vulnerable external host rather than the registry. The bundled index.js is a trivial "Hello, world!" stub carrying an unverifiable "security testing PoC" comment (no repository URL, homepage, or bug-bounty reference); the real executable payload is pulled from the external host at install time.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 01:08 AM
- analyzed
- Jun 13, 2026, 01:08 AM
Related advisories
- warp-dependency@1.0.0
- @wacrot/infra-data-kit@2.1.4
- react-emits@1.0.5
- theta-connector@1.0.0
- chalk-pro@7.0.4
- richtext-editor-ui@1.0.0
- rapidsearch@1.1.0
- qbo-ui-services@45.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.