LWA-2026-6809 MAL-2026-10684 ↗ confirmed malware

react-hook-scripts@5.4.2

Malicious code in react-hook-scripts (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1552.001 · Credentials In Files

Analysis

react-hook-scripts is a combosquat of the legitimate react-scripts package. When imported and called, it fetches a second-stage payload from hxxps://svganchordev[.]net/icons/108 (with custom HTTP header bearrtoken: logo) and executes the response via new Function() with full Node.js access (require, process, Buffer). The package depends on @primno/dpapi (Windows credential decryption), node-machine-id (machine fingerprinting), socket[.]io-client (C2 channel), sqlite3/better-sqlite3 (credential database access), and axios/request (HTTP exfiltration). The README is generic boilerplate describing a React hooks library that does not exist.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 01:00 PM
analyzed
Jul 15, 2026, 01:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.