MAL-2026-14253

    Dashboard / Malicious Package / MAL-2026-14253

    MAL-2026-14253

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in react-dom-helpers (npm)

    Details: Source: amazon-inspector (2fae606be0dbd7c79552511c2553ec9e1d081df1279f0bc85502a6c08c0f17fb) Package name typosquats `react-dom`. On `require('react-dom-helpers/client')`, client.js decodes a base64-obfuscated Slack bot token and channel ID, enumerates local IPv4 addresses via os.networkInterfaces(), fetches the installer's public IP from api.ipify.org, and POSTs the collected host identifiers to https://slack.com/api/chat.postMessage using the hardcoded bearer token. The exfiltration routine is invoked unconditionally at module load. The base64 wrapping of the Slack credential is used to bypass secret scanners.

    Affected packages

    Package

    Name: react-dom-helpers

    Purl: pkg:npm/react-dom-helpers

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.3.3
    MAL-2026-14253 | CVE-DB