MAL-2026-11144

    Dashboard / Malicious Package / MAL-2026-11144

    MAL-2026-11144

    Published: 28 Jul 2026Last Modified: 28 Jul 2026

    Summary: Malicious code in react-puller (npm)

    Details: Source: amazon-inspector (a3ac07c0f6c79714a7b1f6bfd1272f9f7942cf0473875ca5276a1034c084f06d) The package's postinstall hook runs `node index.js`, which spawns a detached worker that downloads two Windows executables (CDPUserPlatform.exe and DOContentCacheMgr.exe) from a hardcoded bare-IP endpoint at http://64.49.11.161:8000 over plain HTTP, writes them into `~/.react-pul`, and launches them via `cmd /c start`. The `addToStartup` routine then writes an HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry pointing at `~/.react-pul/DOContentCacheMgr.exe`, autostarting the dropped binary on every user login. The package name and description present it as a generic React utility, unrelated to the shipped behavior.

    Affected packages

    Package

    Name: react-puller

    Purl: pkg:npm/react-puller

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0