{"id":"MAL-2026-12423","summary":"Malicious code in react-fontawesome-icons (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4706d295cdd6ae07918ab25d54475d97d88e92c8ba2d3923078ba916096b4366)\nThe default-exported React component in react-fontawesome-icons@1.0.3 performs an unconditional axios GET to http://command.control on every render and then POSTs document.cookie (together with a static data payload) to http://commad.control/404. Any consumer application that renders this icon component transmits the user's browser session cookies to a hardcoded non-first-party destination. The source uses cover-story naming and comments (`not_ma_li_ci_ous_at_all`, 'nothing harmful here LOL') and a commented base64 flag-decoder around the exfiltration call, indicating deliberate misdirection rather than accident. The package is presented as a Font Awesome icon component; icon rendering does not require any outbound network traffic, and the destination hosts are not resolvable legitimate infrastructure.\n","modified":"2026-08-05T18:19:46.875368769Z","published":"2026-08-05T12:31:32Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014690","import_time":"2026-08-05T13:08:37.825585964Z","modified_time":"2026-08-05T12:31:32Z","sha256":"06bc9138ae52b505e55664ed2e899a5dba05546a99c9b95622a5295ab68d4102","source":"amazon-inspector","versions":["1.0.6"]},{"source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-014910","import_time":"2026-08-05T14:19:42.129370212Z","modified_time":"2026-08-05T13:10:12Z","sha256":"36a964041c29f69f015fc70f947e1172bd1e8fd92b6292d3014117d4f1c6f191"},{"sha256":"aef5cf6c4b85c34ea671ef8cdab9298c27bced2231983eb09fa9c9a230a0e86c","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014902","import_time":"2026-08-05T14:19:41.416212277Z","modified_time":"2026-08-05T13:09:07Z"},{"source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-014908","import_time":"2026-08-05T14:19:41.937972979Z","modified_time":"2026-08-05T13:09:57Z","sha256":"2e0b2ce40b563a4df5cb30b6b263d7773c69c318ad994e8146219fae8c6fc6b2"},{"id":"IN-MAL-2026-015823","import_time":"2026-08-05T17:04:49.157745806Z","modified_time":"2026-08-05T16:16:16Z","sha256":"426c8f4b23bac2919ce797fd5c4ab1e68b5b231a09d8fa2a26bf65db46360509","source":"amazon-inspector","versions":["1.0.5"]},{"import_time":"2026-08-05T18:07:50.656038312Z","modified_time":"2026-08-05T17:25:55Z","sha256":"4706d295cdd6ae07918ab25d54475d97d88e92c8ba2d3923078ba916096b4366","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-015833"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-fontawesome-icons/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-fontawesome-icons/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-fontawesome-icons/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-fontawesome-icons/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-fontawesome-icons/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-fontawesome-icons/v/1.0.3"}],"affected":[{"package":{"name":"react-fontawesome-icons","ecosystem":"npm","purl":"pkg:npm/react-fontawesome-icons"},"versions":["1.0.6","1.0.2","1.0.1","1.0.4","1.0.5","1.0.3"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"4bb77328be2325aeb8f0b0790fff2d7f45c9b1c5678e4ebb830f025bd9403861","tlsh":"83f09e6f63b850b4413308d5b75dd01de20351663fc6ec04ab597f108bc1229b8672ac","path":"index.jsx"}],"package_integrity":[{"filename":"react-fontawesome-icons-1.0.6.tgz","hashes":{"sha1":"f03d23a26f6d0dc04529eaf8aac191d3ff824efd","sha512_sri":"sha512-3/Ursy9uQwlTsVytzxCSler3lEteM6NyMJMnisK7594c6bD/B2MALG5lGMujZiLvOIrBZyxCjdisywAPQzvLBg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-fontawesome-icons/MAL-2026-12423.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}