react-dynammic-table-component@1.2.7
Malicious code in react-dynammic-table-component (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Typosquat of "react-dynamic-table-component": the preinstall hook (node dist/setup.js) fetches arbitrary JavaScript from hxxps://everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=master and executes it via eval(), giving the remote server full control over the installation environment. The package bundles a legitimate-looking React table component as cover but executes the downloader before the package is usable.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 06:18 PM
- analyzed
- Jun 26, 2026, 06:19 PM
Related advisories
- react-dynamic-table-compenent@1.2.7
- gptmini@4.0.2
- chai-as-assured@7.1.2
- rollup-plugin-polyfill-handler@1.0.0
- ts-einkle-slot@0.0.8
- ts-einkle@1.0.9
- velocityfix@1.0.0
- txs-builder@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.