LWA-2026-5872 MAL-2026-6303 ↗ confirmed malware

react-simple-utils-kit@1.0.4

Malicious code in react-simple-utils-kit (npm)

Analysis

The package react-simple-utils-kit@1.0.4 is a trojanized npm package that runs an SSRF probe and environment-data exfiltration via its postinstall hook (postinstall.js). On installation it: collects hostname, working directory, network configuration (ifconfig, ip route), and the COZE_WORKLOAD_API_TOKEN environment variable; probes cloud metadata endpoints at 169[.]254[.]169[.]254 (AWS), 100[.]100[.]100[.]200 (Alibaba Cloud), and metadata[.]tencentyun[.]com (Tencent Cloud); tests outbound SSRF capability via src-ssrf[.]bytedance[.]net; and POSTs all gathered data to the C2 host 2e3bkumw[.]requestrepo[.]com over HTTP. The package describes itself deceptively as a "date formatting utility for React" and contains no date-formatting code — the sole payload is the installer-side reconnaissance and exfiltration.

analyzed by
Leitwacht
first seen
Jun 23, 2026, 10:56 AM
analyzed
Jun 23, 2026, 11:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.