LWA-2026-5766 MAL-2026-6341 ↗ confirmed malware

react-check-error@2.1.6

Malicious code in react-check-error (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1140 · Deobfuscate/Decode Files or InformationT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

react-check-error@2.1.6 is a typosquat of the legitimate check-error utility by the chai.js project. On require(), it decrypts a hardcoded AES-256-CBC ciphertext using a derived key and IV, revealing hxxps://jsonkeeper[.]com/b/JOCBY. It then fetches that URL over HTTPS, extracts the "cookie" field from the JSON response, and passes it to new Function('require', …)(require) to execute arbitrary remote code. DNS queries and HTTPS connections to jsonkeeper[.]com were confirmed at runtime.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 01:11 PM
analyzed
Jun 19, 2026, 01:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.