LWA-2026-4955 confirmed malware

react-schedule-it@4.0.0

Malicious code in react-schedule-it (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

A downloader/loader. The manifest declares a dependency on itself at hxxp://pack[.]nppacks[.]com/npm/react-schedule-it (HTTP, not HTTPS), so npm install fetches a tarball from an untrusted, MITM-vulnerable external host rather than the registry. The bundled index.js is a trivial "Hello, world!" stub carrying an unverifiable "security testing PoC" comment (no repository URL, homepage, or bug-bounty reference); the real executable payload is pulled from the external host at install time.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 01:08 AM
analyzed
Jun 13, 2026, 01:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.