react-tabulix-ui@0.1.2
Malicious code in react-tabulix-ui (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
react-tabulix-ui@0.1.2 is a trojanized React table component. The package ships a preinstall hook (dist/index.d.js) that base64-decodes a payload which fetches arbitrary JavaScript from everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=root2 and executes it via eval. The legitimate table component in dist/index.js and dist/index.mjs is a decoy — the malicious behaviour runs at install time before the package is used.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 05:46 PM
- analyzed
- Jul 22, 2026, 05:47 PM
Related advisories
- encryptstringadmin@1.2.1
- poly-provider-api@4.6.1
- async-mutex-lock@5.3.1
- dbconnectify@1.0.2
- utility-kit-ts@1.3.2
- ts-toolkit-plus@1.3.2
- ventrix-kit@1.5.2
- @copilot-mcp/apex@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.