MAL-2026-15691

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-hook-doms/MAL-2026-15691.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-15691
Published
2026-08-24T17:06:31Z
Modified
2026-09-09T03:30:11Z
Summary
Malicious code in react-hook-doms (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a01d746e2ab5362af396f0bafe921bcd6aed22b8321555ccb16d0f8f7a5c9183)

The package was found to contain malicious code or consuming dependency that contains malicious code

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "RLMA-2026-06416",
            "import_time":  "2026-09-01T11:17:33.795474928Z",
            "modified_time":  "2026-08-24T17:06:31Z",
            "sha256":  "cf0fcc32726b80508639313a81e0d4a12b526609eb89c58edeba1f1198969dc7",
            "source":  "reversing-labs",
            "versions":  [
                "5.3.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-019791",
            "import_time":  "2026-09-09T03:21:54.003883439Z",
            "modified_time":  "2026-09-09T02:46:24Z",
            "sha256":  "a01d746e2ab5362af396f0bafe921bcd6aed22b8321555ccb16d0f8f7a5c9183",
            "source":  "amazon-inspector",
            "versions":  [
                "5.3.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / react-hook-doms

Package

Name
react-hook-doms
View open source insights on deps.dev
Purl
pkg:npm/react-hook-doms

Affected ranges

Affected versions

5.*
5.3.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity":  [
        {
            "filename":  "react-hook-doms-5.3.1.tgz",
            "hashes":  {
                "sha1":  "edbab6b217b97185d383449c1856c20b126da689",
                "sha512_sri":  "sha512-0p+jiQuw7sZN9cEeyEDjX/by4lSK0n7zKfpDgx41ysqiybAcHK6j+YxHaBR3UPaN+U/5v3dJYKn6hsSRJd6EFA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-hook-doms/MAL-2026-15691.json"