MAL-2026-4631

    Dashboard / Malicious Package / MAL-2026-4631

    MAL-2026-4631

    Published: 25 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in opentiny-react (npm)

    Details: Source: amazon-inspector (70307cffed06951bdb7b961e7846e3b3e0ba660b75ddca0b4fa11366ab94dc6d) The package `opentiny-react` reproduces the source, README, and CHANGELOG of the legitimate `@tinymce/tinymce-react` integration verbatim under a confusable unscoped name. Its `package.json` falsifies the author as 'Ephox Corporation DBA Tiny Technologies, Inc.' while the repository points to `github.com/mild-blue/opentiny-react`, which is not the real Tiny organization (`tinymce/tinymce-react`). The wrapper itself ships no runtime payload, but `package.json` declares `"opentiny": "6.9.31"` as a runtime dependency — a name that mimics `tinymce` and is pinned to the same 6.9.31 version as this wrapper, consistent with a coordinated impersonation cluster. A real `@tinymce/tinymce-react` installation pulls `tinymce`, not `opentiny`. Installing `opentiny-react` silently pulls the attacker-controlled `opentiny` package into the dependency tree where its install-time and import-time code will execute against the installer.

    Affected packages

    Package

    Name: opentiny-react

    Purl: pkg:npm/opentiny-react

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.9.31
    MAL-2026-4631 | CVE-DB