react-hot-svg@1.1.5
Malicious code in react-hot-svg (npm)
Analysis
react-hot-svg@1.1.5 is a trojanized SVG utility. When a developer requires the module and calls getPlugin() or setPlugin(), the code decodes a base64-embedded command and spawns `npm install rollup-plugin-polyfill-handler --no-save --silent --no-audit --no-fund`, installing a second-stage package without saving it to package.json and suppressing all npm warnings. It then requires and executes that package. The second-stage package name typosquats the legitimate rollup-plugin-polyfill family. The package has no install hooks, so the payload only runs when the module's functions are explicitly called.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 04:51 PM
- analyzed
- Jul 11, 2026, 04:52 PM
Related advisories
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- multer-orm@2.0.2
- theme-color-picker@2.0.28
- web3-token-helper@1.1.3
- node-fetch-utils@1.2.1
- @caspianph/storyteller@1.1.13
- macos-ci-utils@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.