react-hook-use-debounce-throttle-12@1.0.0
Malicious code in react-hook-use-debounce-throttle-12 (npm)
Analysis
This package ships a postinstall lifecycle script that executes automatically when the package is installed. The script spawns node -e and issues an outbound HTTPS GET request to a hardcoded raw IP address (8[.]140[.]205[.]78) on port 80, with a short timeout and all errors silently suppressed. This is an install-time beacon: it phones home to an external host on every install to confirm code execution and leak the installing host to the operator. There is no legitimate reason for a React debounce/throttle hook library to contact a hardcoded IP at install time. The package name imitates a generic React hook utility and the publishing account does not match the declared author.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 03:47 PM
- analyzed
- Jun 16, 2026, 03:52 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.