LWA-2026-6432 MAL-2026-10211 ↗ confirmed malware

react-next-vite@1.2.9

Malicious code in react-next-vite (npm)

Analysis

The package react-next-vite@1.2.9 is a combosquat of the React, Next.js, and Vite framework names. Its entry point (index.js) spawns a detached background Node.js process that fetches a remote payload from an IPFS URL hosted on the Pinata gateway (bronze-improved-gibbon-411[.]mypinata[.]cloud/ipfs/bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu) and executes the returned code via the Function constructor, enabling arbitrary remote code execution on the installer's machine. The package has no repository URL and its description is unrelated to its name.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 04:07 PM
analyzed
Jul 7, 2026, 04:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.