react-fast-refresh-helper@1.2.6
Malicious code in react-fast-refresh-helper (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File
Analysis
The postinstall hook (node install.js) downloads a binary from raw[.]githubusercontent[.]com/Dunals/kl/main/keylogger.exe, writes it to the system temp directory as chrome_<timestamp>.exe, sets it executable, and spawns it as a detached process before exiting. The package's main entry point is an empty stub (module.exports = {}), and the package.json claims authorship as "Meta Open Source" — a trojanized impersonation of a React development utility. The binary is fetched over HTTPS from a GitHub raw content URL under the Dunals account.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 07:54 AM
- analyzed
- Jul 30, 2026, 07:55 AM
Related advisories
- express-middle@5.5.1
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
- chain-analyze@1.0.2
- react-puller@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.