MAL-2026-14253
Dashboard / Malicious Package / MAL-2026-14253
MAL-2026-14253
Summary: Malicious code in react-dom-helpers (npm)
Details: Source: amazon-inspector (2fae606be0dbd7c79552511c2553ec9e1d081df1279f0bc85502a6c08c0f17fb) Package name typosquats `react-dom`. On `require('react-dom-helpers/client')`, client.js decodes a base64-obfuscated Slack bot token and channel ID, enumerates local IPv4 addresses via os.networkInterfaces(), fetches the installer's public IP from api.ipify.org, and POSTs the collected host identifiers to https://slack.com/api/chat.postMessage using the hardcoded bearer token. The exfiltration routine is invoked unconditionally at module load. The base64 wrapping of the Slack credential is used to bypass secret scanners.
Affected packages
Package
Name: react-dom-helpers
Purl: pkg:npm/react-dom-helpers
Affected ranges
Type: N/A
Events:
