LWA-2026-6027 MAL-2026-6534 ↗ confirmed malware

react-dynammic-table-component@1.2.7

Malicious code in react-dynammic-table-component (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Typosquat of "react-dynamic-table-component": the preinstall hook (node dist/setup.js) fetches arbitrary JavaScript from hxxps://everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=master and executes it via eval(), giving the remote server full control over the installation environment. The package bundles a legitimate-looking React table component as cover but executes the downloader before the package is usable.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 06:18 PM
analyzed
Jun 26, 2026, 06:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.