react-hook-scripts@5.4.2
Malicious code in react-hook-scripts (npm)
Analysis
react-hook-scripts is a combosquat of the legitimate react-scripts package. When imported and called, it fetches a second-stage payload from hxxps://svganchordev[.]net/icons/108 (with custom HTTP header bearrtoken: logo) and executes the response via new Function() with full Node.js access (require, process, Buffer). The package depends on @primno/dpapi (Windows credential decryption), node-machine-id (machine fingerprinting), socket[.]io-client (C2 channel), sqlite3/better-sqlite3 (credential database access), and axios/request (HTTP exfiltration). The README is generic boilerplate describing a React hooks library that does not exist.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 01:00 PM
- analyzed
- Jul 15, 2026, 01:01 PM
Related advisories
- @web3-helpers/core@1.0.5
- eth-wallet-helpers@1.0.0
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
- arb-kit@1.0.1
- base58-utils@1.0.3
- eth-dev@1.0.2
- abi-encode@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.