react-fontawesome-icons@1.0.5
Malicious code in react-fontawesome-icons (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
react-fontawesome-icons is a combosquat of the legitimate @fortawesome/react-fontawesome package. The component's index.jsx file exfiltrates the user's cookies to two external hosts (command.control and commad.control) via HTTP POST requests using the axios library. When a website imports and renders the FontAwesomeIcon component, it silently sends document.cookie to hxxp://command[.]control and hxxp://commad[.]control/404.
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 04:30 AM
- analyzed
- Jul 23, 2026, 04:30 AM
Related advisories
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
- parket-helper@0.0.1
- textdecode@1.2.7
- pocbitbarrontest@1.0.0
- pino-pretty-logger@1.1.1
- packageuwu@1.0.1
- gekko-mev-bot@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.