{"id":"MAL-2026-1836","summary":"Malicious code in react-performance-suite (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4e8467a722c92d3c846a99ea30e0b092dd93fba781c34f93dae9b05582d4475e)\nThe package react-performance-suite was found to contain malicious code.\n","modified":"2026-04-16T15:49:24.654963Z","published":"2026-03-18T13:07:05Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-03-19T12:19:08.802834513Z","source":"reversing-labs","id":"RLMA-2026-01533","versions":["2.0.0","2.0.1"],"sha256":"a4da620335e14f78a181c7e9a70b30d30487cf8ef5eb6796c44393a0996d4d3c","modified_time":"2026-03-18T13:07:05Z"},{"import_time":"2026-03-23T05:14:27.701936502Z","source":"amazon-inspector","versions":["2.0.0","2.0.1"],"sha256":"4e8467a722c92d3c846a99ea30e0b092dd93fba781c34f93dae9b05582d4475e","modified_time":"2026-03-23T05:11:41Z"},{"import_time":"2026-04-16T15:39:32.719711882Z","source":"reversing-labs","id":"RLUA-2026-02031","sha256":"3dac780d6971f862a06876656cf8f0192c8ca48dd6a463049535c42b41f4661e","modified_time":"2026-04-16T10:14:44Z"}]},"references":[{"type":"ARTICLE","url":"https://www.reversinglabs.com/blog/npm-fake-install-logs-rat"}],"affected":[{"package":{"name":"react-performance-suite","ecosystem":"npm","purl":"pkg:npm/react-performance-suite"},"versions":["2.0.0","2.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-performance-suite/MAL-2026-1836.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}