react-check-error@2.1.6
Malicious code in react-check-error (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1140 · Deobfuscate/Decode Files or InformationT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
react-check-error@2.1.6 is a typosquat of the legitimate check-error utility by the chai.js project. On require(), it decrypts a hardcoded AES-256-CBC ciphertext using a derived key and IV, revealing hxxps://jsonkeeper[.]com/b/JOCBY. It then fetches that URL over HTTPS, extracts the "cookie" field from the JSON response, and passes it to new Function('require', …)(require) to execute arbitrary remote code. DNS queries and HTTPS connections to jsonkeeper[.]com were confirmed at runtime.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 01:11 PM
- analyzed
- Jun 19, 2026, 01:11 PM
Related advisories
- chai-assert-kit@3.8.1
- the_tax_free_cashier_is_at_9f@1995.3.20
- webpack-patch@1.1.7
- wao@0.41.2
- stylelint-standard@1.2.0
- macos-ci-utils@1.0.1
- react-next-dom@1.1.7
- node-pino@2.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.