Logo
npm

reactjs-risk@99.17.4

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:15 PM UTC

Malicious

OSV ID

MAL-2026-17339

Ecosystem

npm

Summary

The package's preinstall lifecycle script collects host identity metadata from the installer machine — os.hostname(), the output of whoami/os.userInfo().username, and os.platform() — hex-encodes the values, and issues a DNS A-record lookup for <hex>.768hgkqn53abdemu8ikzkel4g.canarytokens.com, causing the installer's hostname, username, and platform to be transmitted to the canarytoken operator on every npm install. The dns module is loaded via string concatenation ('d'+'n'+'s') and the whoami command is similarly split, indicating deliberate obfuscation of the module and command names. The package's declared main entry is an empty stub with no library functionality, so the preinstall beacon is the package's only behavior. Installing this package auto-executes an unauthenticated exfiltration of installer identity metadata to a third-party DNS endpoint the installer did not opt into.

Source: amazon-inspector (0e58c82916c5199ef9e73a5d70f91d120312151eb5c28090d8bbf6dbf4117543)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.