react-puller@1.0.0
Malicious code in react-puller (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1204.002 · Malicious File
Analysis
The package's postinstall hook runs index.js, which spawns a detached child process that downloads two Windows executables (CDPUserPlatform.exe and DOContentCacheMgr.exe) from hxxp://64[.]49[.]11[.]161:8000/share/ into ~/.react-pul/. It then adds DOContentCacheMgr.exe to the Windows startup registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) for persistence and launches both executables via cmd.exe /c start. The downloader includes retry logic with exponential backoff and supports resuming partial downloads.
- analyzed by
- Leitwacht
- first seen
- Jul 27, 2026, 11:35 PM
- analyzed
- Jul 27, 2026, 11:36 PM
Related advisories
- system-performance-helper@1.0.1
- my-tailwind-gutenberg-block@0.1.2
- mcp-dev-toolkit@1.5.0
- pinokio-redis@1.0.127
- zod-pino434@1.0.127
- crypto-base58@1.0.1
- base58-cli@1.0.0
- pino-zod@1.0.121
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.