react-v17@20.0.1
Malicious code in react-v17 (npm)
Analysis
Package react-v17@20.0.1 is a combosquat of the real react package. Its preinstall hook (node index.js) collects system information — hostname, platform, architecture, username, uid/gid, shell, OS release, CPU count, current working directory, and output of the whoami and id commands — then POSTs the data as JSON to hxxps://1jlay7gzya8akcmqs8repdf7oyupim6b[.]oastify[.]com/detox56 (an OAST/Interact.sh callback endpoint). The package also ships a file named 'i' containing Instagram follower data of unknown provenance, suggesting the publisher harvested social-media accounts.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 01:06 PM
- analyzed
- Jul 3, 2026, 01:08 PM
Related advisories
- yiyuan-api@1.0.3
- giantswarm@22.0.1
- @broadpeak/smartlib-ad@24.1.10
- unreal-horde-dashboard@99999.0.0
- ue-jenkins-buildkite@99999.0.0
- epic-internal-tools@99999.0.0
- robomerge@99999.0.0
- webrix-docs1@10.2.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.