LWA-2026-7354 MAL-2026-11427 ↗ confirmed malware

pp-react-worldready@1.0.0

Malicious code in pp-react-worldready (npm)

Analysis

The packages pp-react-worldready and pp-react-worldready-v5 are typosquat malware that exfiltrate CI/CD environment metadata at install time. The preinstall hook (vishu.js) performs external IP lookup via api[.]ipify[.]org, sends DNS beacons to an oastify[.]com subdomain for CI/CD fingerprinting, and exfiltrates environment variables (ci, gh_act, gh_wf) to webhook[.]site via HTTPS. The payload reads hostname, platform, and CI/CD environment variables, then beacons the data to the C2 at webhook[.]site/1b840cbf-f1a4-4d79-bf11-f1ef62949110 and via DNS to ping-build-*.your-collab-domain[.]oastify[.]com.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 01:55 PM
analyzed
Aug 1, 2026, 04:04 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.