LWA-2026-6797 confirmed malware
react-hook-doms@5.3.1
Malicious code in react-hook-doms (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat of react-dom. The package's main entry point (index.js) fetches a remote payload from svganchordev[.]net/icons/108 and executes it via the Function constructor with full Node.js capabilities (require, process, Buffer) passed into the execution context. Any project importing this package will download and run arbitrary code from the remote server. The package ships no actual React hooks — only the remote code execution downloader.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 02:45 AM
- analyzed
- Jul 15, 2026, 02:47 AM
Related advisories
- assertion-utils-js@2.4.3
- @risaoffc/baileys@8.0.3
- chai-as-hardened@7.0.9
- @asyncapi/specs@6.11.2
- @asyncapi/generator-helpers@1.1.1
- eth-wallet-helpers@1.0.0
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.