react-simple-utils-kit@1.0.4
Malicious code in react-simple-utils-kit (npm)
Analysis
The package react-simple-utils-kit@1.0.4 is a trojanized npm package that runs an SSRF probe and environment-data exfiltration via its postinstall hook (postinstall.js). On installation it: collects hostname, working directory, network configuration (ifconfig, ip route), and the COZE_WORKLOAD_API_TOKEN environment variable; probes cloud metadata endpoints at 169[.]254[.]169[.]254 (AWS), 100[.]100[.]100[.]200 (Alibaba Cloud), and metadata[.]tencentyun[.]com (Tencent Cloud); tests outbound SSRF capability via src-ssrf[.]bytedance[.]net; and POSTs all gathered data to the C2 host 2e3bkumw[.]requestrepo[.]com over HTTP. The package describes itself deceptively as a "date formatting utility for React" and contains no date-formatting code — the sole payload is the installer-side reconnaissance and exfiltration.
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 10:56 AM
- analyzed
- Jun 23, 2026, 11:33 AM
Related advisories
- react-simple-utils-kit@1.0.1 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.