MAL-2026-17339

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/reactjs-risk/MAL-2026-17339.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17339
Published
2026-09-30T09:30:37Z
Modified
2026-09-30T15:00:05Z
Summary
Malicious code in reactjs-risk (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (0e58c82916c5199ef9e73a5d70f91d120312151eb5c28090d8bbf6dbf4117543)

The package's preinstall lifecycle script collects host identity metadata from the installer machine — os.hostname(), the output of whoami/os.userInfo().username, and os.platform() — hex-encodes the values, and issues a DNS A-record lookup for <hex>.768hgkqn53abdemu8ikzkel4g.canarytokens.com, causing the installer's hostname, username, and platform to be transmitted to the canarytoken operator on every npm install. The dns module is loaded via string concatenation ('d'+'n'+'s') and the whoami command is similarly split, indicating deliberate obfuscation of the module and command names. The package's declared main entry is an empty stub with no library functionality, so the preinstall beacon is the package's only behavior. Installing this package auto-executes an unauthenticated exfiltration of installer identity metadata to a third-party DNS endpoint the installer did not opt into.

Source: ossf-package-analysis (a32a318956967c92b753750e0b607e48db7eef07d05f25c2b687f3b9612f806e)

The OpenSSF Package Analysis project identified 'reactjs-risk' @ 99.17.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins":  [
        {
            "import_time":  "2026-09-30T09:46:26.826943396Z",
            "modified_time":  "2026-09-30T09:30:37Z",
            "sha256":  "a32a318956967c92b753750e0b607e48db7eef07d05f25c2b687f3b9612f806e",
            "source":  "ossf-package-analysis",
            "versions":  [
                "99.17.1"
            ]
        },
        {
            "import_time":  "2026-09-30T10:20:20.592074968Z",
            "modified_time":  "2026-09-30T09:55:47Z",
            "sha256":  "7bb6a3319bd95ae759acafaee820c331f78291170c6895d06f5c0e78c761afd2",
            "source":  "ossf-package-analysis",
            "versions":  [
                "99.17.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-020824",
            "import_time":  "2026-09-30T14:21:25.406710779Z",
            "modified_time":  "2026-09-30T14:05:35Z",
            "sha256":  "0e58c82916c5199ef9e73a5d70f91d120312151eb5c28090d8bbf6dbf4117543",
            "source":  "amazon-inspector",
            "versions":  [
                "99.17.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-020823",
            "import_time":  "2026-09-30T14:21:25.321757098Z",
            "modified_time":  "2026-09-30T14:05:24Z",
            "sha256":  "3a5dc3ce9adff40ece4797ddd3349d25cc9e587737bde995ce0038740f72c56b",
            "source":  "amazon-inspector",
            "versions":  [
                "99.17.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020828",
            "import_time":  "2026-09-30T14:46:12.515689658Z",
            "modified_time":  "2026-09-30T14:30:31Z",
            "sha256":  "54ea883450b7f65285f08f4610b55333d89153938d2618de98f2857b3b9053ca",
            "source":  "amazon-inspector",
            "versions":  [
                "99.9.9"
            ]
        },
        {
            "id":  "IN-MAL-2026-020827",
            "import_time":  "2026-09-30T14:46:12.429965559Z",
            "modified_time":  "2026-09-30T14:30:23Z",
            "sha256":  "834b02617e1065531a64b675b64d6d003f8c79f6c2fc9fd9779f259c5bf05ef4",
            "source":  "amazon-inspector",
            "versions":  [
                "99.17.4"
            ]
        },
        {
            "id":  "IN-MAL-2026-020825",
            "import_time":  "2026-09-30T14:46:12.193137634Z",
            "modified_time":  "2026-09-30T14:30:01Z",
            "sha256":  "a808d3c4997253da115154c5466b69ef5f4138bdb07398a475a20d54bfcba303",
            "source":  "amazon-inspector",
            "versions":  [
                "99.12.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020826",
            "import_time":  "2026-09-30T14:46:12.316348692Z",
            "modified_time":  "2026-09-30T14:30:14Z",
            "sha256":  "cf0f2c8b571beb70f6c3a64b36b88bad2c3566e4889e7545eb781589921761a7",
            "source":  "amazon-inspector",
            "versions":  [
                "99.17.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / reactjs-risk

Package

Affected ranges

Affected versions

99.*
99.9.9
99.12.0
99.17.0
99.17.1
99.17.2
99.17.4

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "poc.js",
            "sha256":  "5292bd901e13ce268893b18ff670d10b3dcc305ca08d0ce95a6dfe14ea5da4a6",
            "tlsh":  "c201d31317b162a4416119c1db9b84245053f3533512d1e87a9ec3465fd75904a733f5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "reactjs-risk-99.17.2.tgz",
            "hashes":  {
                "sha1":  "8c24f8798f3a55696d4bed5bbe5e540b6381a4fb",
                "sha512_sri":  "sha512-K40VN3M1DDdwO8Wtc3zfVTIPqK4RZPf+QE/q33ExGcl2PCybyv4xuInj1EIPyl43SDDpDhYU7I881ZK+Mmh7/Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/reactjs-risk/MAL-2026-17339.json"