{"id":"MAL-2026-15691","summary":"Malicious code in react-hook-doms (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a01d746e2ab5362af396f0bafe921bcd6aed22b8321555ccb16d0f8f7a5c9183)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n","modified":"2026-09-09T03:30:11.021557695Z","published":"2026-08-24T17:06:31Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-01T11:17:33.795474928Z","modified_time":"2026-08-24T17:06:31Z","sha256":"cf0fcc32726b80508639313a81e0d4a12b526609eb89c58edeba1f1198969dc7","source":"reversing-labs","versions":["5.3.1"],"id":"RLMA-2026-06416"},{"modified_time":"2026-09-09T02:46:24Z","sha256":"a01d746e2ab5362af396f0bafe921bcd6aed22b8321555ccb16d0f8f7a5c9183","source":"amazon-inspector","versions":["5.3.1"],"id":"IN-MAL-2026-019791","import_time":"2026-09-09T03:21:54.003883439Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-hook-doms/v/5.3.1"}],"affected":[{"package":{"name":"react-hook-doms","ecosystem":"npm","purl":"pkg:npm/react-hook-doms"},"versions":["5.3.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-hook-doms/MAL-2026-15691.json","indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-0p+jiQuw7sZN9cEeyEDjX/by4lSK0n7zKfpDgx41ysqiybAcHK6j+YxHaBR3UPaN+U/5v3dJYKn6hsSRJd6EFA==","sha1":"edbab6b217b97185d383449c1856c20b126da689"},"filename":"react-hook-doms-5.3.1.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}