{"id":"MAL-2026-7020","summary":"Malicious code in react-v17 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (73dab7161ffcaee5f943894308dd75428e9081b872daaed7ef50218bf98ad44a)\nPackage name 'react-v17' impersonates the legitimate 'react' package. package.json declares a preinstall hook 'node index.js' that auto-executes on npm install. index.js collects installer identity and host details (os.hostname(), os.userInfo(), os.platform/arch, home directory, cwd) and runs 'whoami' and 'id' via child_process.exec, then HTTPS POSTs the aggregate JSON to a hardcoded Burp Collaborator OOB endpoint at https://1jlay7gzya8akcmqs8repdf7oyupim6b.oastify.com/detox56. The tarball also ships an undeclared ~10.9 KB file 'i' next to index.js that is not referenced by package.json or index.js.\n","modified":"2026-07-08T19:46:40.164069836Z","published":"2026-07-08T19:30:12Z","database_specific":{"malicious-packages-origins":[{"sha256":"73dab7161ffcaee5f943894308dd75428e9081b872daaed7ef50218bf98ad44a","source":"amazon-inspector","versions":["20.0.1"],"id":"IN-MAL-2026-008252","import_time":"2026-07-08T19:33:49.779663036Z","modified_time":"2026-07-08T19:30:12Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/react-v17/v/20.0.1"}],"affected":[{"package":{"name":"react-v17","ecosystem":"npm","purl":"pkg:npm/react-v17"},"versions":["20.0.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"react-v17-20.0.1.tgz","hashes":{"sha1":"2b46e2d8cfb82d7d5207f78da95322619fa3e11a","sha512_sri":"sha512-+eeDnXgw5mbLVewYC+8dMWTmlwfV4vplieN02S8vWdrJY0RpX0XVSyCwfGhWyuNFBlqThpQLsu26DUWavsGejw=="}}],"evidence_files":[{"tlsh":"e45161c505f65a241ba7b8494a4f9402b227e0033605de55bfcc8740af9937c9bf0bf2","path":"index.js","sha256":"7abadd376ce6457fa7ddeb8b81c18473d480fdb7505903b690ab162996544392"},{"path":"i","sha256":"5a80c722939ba6f3373043432a13cefcf6b36a52124ed1e6d261dbecd428953a","tlsh":"d72288760912a800a723bdd54ee8ec5e25e8e47d621f683cf456efb62b8c14d5f1e123"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-v17/MAL-2026-7020.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}