{"id":"MAL-2026-10605","summary":"Malicious code in @radivi-ui/react-dialog (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b5e92ae03eb6adb090fb832665431984cccef31039bb920e3850535f4defe610)\n@radivi-ui/react-dialog is a typosquat of @radix-ui/react-dialog whose main entry (index.js) is a self-executing IIFE that runs `whoami` and `hostname` via `child_process.execSync` when the package is loaded via require/import. The command outputs are hex-encoded and exfiltrated to the hardcoded Burp Collaborator subdomain `vih2vewj1xxwlsd8dkgjqugtyk4bs1gq.oastify.com` via both DNS resolution (dns.resolve of a crafted subdomain) and HTTP GET (http.get). The behavior fires unconditionally on module load with no user opt-in, no CLI gate, and no relation to any dialog/UI functionality the package name implies.\n","modified":"2026-07-14T18:49:31.785145042Z","published":"2026-07-14T17:55:20Z","database_specific":{"malicious-packages-origins":[{"sha256":"725caff8c13b83aaf4d33c43808c73a1cb2e0f0a7f70ea8960ee376f75a2ae02","source":"amazon-inspector","versions":["1.1.3"],"id":"IN-MAL-2026-010541","import_time":"2026-07-14T18:28:27.768365791Z","modified_time":"2026-07-14T17:55:30Z"},{"id":"IN-MAL-2026-010540","import_time":"2026-07-14T18:28:27.660661969Z","modified_time":"2026-07-14T17:55:20Z","sha256":"b5e92ae03eb6adb090fb832665431984cccef31039bb920e3850535f4defe610","source":"amazon-inspector","versions":["1.1.4"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@radivi-ui/react-dialog/v/1.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@radivi-ui/react-dialog/v/1.1.4"}],"affected":[{"package":{"name":"@radivi-ui/react-dialog","ecosystem":"npm","purl":"pkg:npm/%40radivi-ui/react-dialog"},"versions":["1.1.3","1.1.4"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"ac53e3207632117bc595d6fa996a321d014d0aa26068af339d813a823a7be135","tlsh":"9351336916fe33341bf3b8d8ea036052bc0e62507419ee91f9ed1f210fca624a2561fd"}],"package_integrity":[{"filename":"react-dialog-1.1.3.tgz","hashes":{"sha1":"05eafef9fc6b3590c16baa7dd357c83581c6217e","sha512_sri":"sha512-6evztCQeDvQe1fHvpIItKAivcBAoVuEdmFL3kXynBRtm+FFNxl+Pa+p4HFcS8a8u4L1Yqiod/r8VVCZz9hMF5w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@radivi-ui/react-dialog/MAL-2026-10605.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}