LWA-2026-6026 MAL-2026-6533 ↗ confirmed malware

react-dynamic-table-compenent@1.2.7

Malicious code in react-dynamic-table-compenent (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

A typosquat of a React table component ("compenent" vs. "component") that executes a remote code downloader during npm install. The package's postinstall script (dist/setup.js) fetches an arbitrary JavaScript payload from everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=master via HTTPS and evals it, giving the remote server full control over what code runs on the installer's machine. The main library file (dist/index.js) is a legitimate-looking React table component shipped as camouflage.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 06:18 PM
analyzed
Jun 26, 2026, 06:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.