LWA-2026-5575 MAL-2026-5909 ↗ confirmed malware

react-hook-use-debounce-throttle-12@1.0.0

Malicious code in react-hook-use-debounce-throttle-12 (npm)

Analysis

This package ships a postinstall lifecycle script that executes automatically when the package is installed. The script spawns node -e and issues an outbound HTTPS GET request to a hardcoded raw IP address (8[.]140[.]205[.]78) on port 80, with a short timeout and all errors silently suppressed. This is an install-time beacon: it phones home to an external host on every install to confirm code execution and leak the installing host to the operator. There is no legitimate reason for a React debounce/throttle hook library to contact a hardcoded IP at install time. The package name imitates a generic React hook utility and the publishing account does not match the declared author.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 03:47 PM
analyzed
Jun 16, 2026, 03:52 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.