LWA-2026-7242 MAL-2026-11366 ↗ confirmed malware

react-fast-refresh-helper@1.2.6

Malicious code in react-fast-refresh-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File

Analysis

The postinstall hook (node install.js) downloads a binary from raw[.]githubusercontent[.]com/Dunals/kl/main/keylogger.exe, writes it to the system temp directory as chrome_<timestamp>.exe, sets it executable, and spawns it as a detached process before exiting. The package's main entry point is an empty stub (module.exports = {}), and the package.json claims authorship as "Meta Open Source" — a trojanized impersonation of a React development utility. The binary is fetched over HTTPS from a GitHub raw content URL under the Dunals account.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 07:54 AM
analyzed
Jul 30, 2026, 07:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.