MAL-2026-11144
Dashboard / Malicious Package / MAL-2026-11144
MAL-2026-11144
Summary: Malicious code in react-puller (npm)
Details: Source: amazon-inspector (a3ac07c0f6c79714a7b1f6bfd1272f9f7942cf0473875ca5276a1034c084f06d) The package's postinstall hook runs `node index.js`, which spawns a detached worker that downloads two Windows executables (CDPUserPlatform.exe and DOContentCacheMgr.exe) from a hardcoded bare-IP endpoint at http://64.49.11.161:8000 over plain HTTP, writes them into `~/.react-pul`, and launches them via `cmd /c start`. The `addToStartup` routine then writes an HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry pointing at `~/.react-pul/DOContentCacheMgr.exe`, autostarting the dropped binary on every user login. The package name and description present it as a generic React utility, unrelated to the shipped behavior.
Affected packages
Package
Name: react-puller
Purl: pkg:npm/react-puller
Affected ranges
Type: N/A
Events:
