computerrock-babel-preset-react-app@15.12.11
Malicious code in computerrock-babel-preset-react-app (npm)
Analysis
The combosquat package computerrock-babel-preset-react-app (typo-squatting babel-preset-react-app from Create React App) runs an automatic preinstall script (node index.js) during npm install. This script collects detailed system information — hostname, current user (whoami, id), working directory (pwd), platform, architecture, home directory, username, uid/gid, shell, OS type/release, total/free memory, and CPU count — and POSTs it as a JSON payload to hxxps://0bccssrkeubggq24k750nrw0erki88wx[.]oastify[.]com/detox56 (an attacker-controlled OAST/interaction-capture server). No user interaction required; the exfiltration is silent.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 01:48 PM
- analyzed
- Jun 18, 2026, 01:49 PM
Related advisories
- @onum-releases/utils@1.0.1
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/transaction-js@99.99.99
- @dxcl/user-js@99.99.99
- @dxcl/account-js@99.99.99
- @dxcl/customer-js@99.99.99
- color-utils-eee0@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.