react-dynamic-table-compenent@1.2.7
Malicious code in react-dynamic-table-compenent (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
A typosquat of a React table component ("compenent" vs. "component") that executes a remote code downloader during npm install. The package's postinstall script (dist/setup.js) fetches an arbitrary JavaScript payload from everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=master via HTTPS and evals it, giving the remote server full control over what code runs on the installer's machine. The main library file (dist/index.js) is a legitimate-looking React table component shipped as camouflage.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 06:18 PM
- analyzed
- Jun 26, 2026, 06:18 PM
Related advisories
- gptmini@4.0.2
- chai-as-assured@7.1.2
- rollup-plugin-polyfill-handler@1.0.0
- ts-einkle-slot@0.0.8
- ts-einkle@1.0.9
- velocityfix@1.0.0
- txs-builder@1.0.6
- ref-slot@1.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.