LWA-2026-5725 MAL-2026-6131 ↗ confirmed malware

computerrock-babel-preset-react-app@15.12.11

Malicious code in computerrock-babel-preset-react-app (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The combosquat package computerrock-babel-preset-react-app (typo-squatting babel-preset-react-app from Create React App) runs an automatic preinstall script (node index.js) during npm install. This script collects detailed system information — hostname, current user (whoami, id), working directory (pwd), platform, architecture, home directory, username, uid/gid, shell, OS type/release, total/free memory, and CPU count — and POSTs it as a JSON payload to hxxps://0bccssrkeubggq24k750nrw0erki88wx[.]oastify[.]com/detox56 (an attacker-controlled OAST/interaction-capture server). No user interaction required; the exfiltration is silent.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 01:48 PM
analyzed
Jun 18, 2026, 01:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.