MAL-2026-6597: Malicious code in @longzy/react-native-polyfill (npm)
The npm package @longzy/react-native-polyfill is identified as purpose-built malware that exfiltrates sensitive host information and environment secrets during installation. It executes a postinstall hook that collects data such as hostname, username, platform, Node version, IP addresses, and the entire process environment variables, which may include tokens and keys. The stolen data is sent to an attacker-controlled Feishu/Lark webhook endpoint. The malware includes multiple obfuscation and anti-analysis techniques to evade detection and sandbox environments.
AI Analysis
Technical Summary
This threat involves a malicious npm package, @longzy/react-native-polyfill, which runs a postinstall script during npm install to collect and exfiltrate host and environment information. The exfiltrated data includes hostname, username, platform, Node.js version, non-internal IP addresses, registry URL, and the full process environment variables, potentially exposing sensitive secrets such as AWS keys and tokens. The data is sent to an attacker-controlled Feishu/Lark bot webhook URL, which is obfuscated using character code transformations and XOR encoding. The malware employs extensive anti-analysis checks, including detection of honeypot tokens, sandbox environment variables, CI environment indicators, and suspicious hostnames or usernames, to avoid execution in analysis environments. The obfuscation and anti-analysis measures are designed to evade casual review and automated detection.
Potential Impact
The malware can lead to the exposure of sensitive environment variables and secrets, including tokens and AWS keys, from developer and CI environments. This exposure can result in unauthorized access to cloud resources, data breaches, and further compromise of development and deployment pipelines. The stealthy exfiltration and anti-analysis features increase the likelihood of prolonged undetected presence in affected environments.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. Users should immediately remove @longzy/react-native-polyfill from their projects and audit their environment for potential secret exposure. Rotate any potentially compromised secrets such as tokens and AWS keys. Avoid installing packages from untrusted sources and monitor dependency trees for suspicious or unknown packages. Since this is a malicious package rather than a vulnerability in legitimate software, remediation involves removal and secret rotation rather than patching.
MAL-2026-6597: Malicious code in @longzy/react-native-polyfill (npm)
Description
The npm package @longzy/react-native-polyfill is identified as purpose-built malware that exfiltrates sensitive host information and environment secrets during installation. It executes a postinstall hook that collects data such as hostname, username, platform, Node version, IP addresses, and the entire process environment variables, which may include tokens and keys. The stolen data is sent to an attacker-controlled Feishu/Lark webhook endpoint. The malware includes multiple obfuscation and anti-analysis techniques to evade detection and sandbox environments.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a malicious npm package, @longzy/react-native-polyfill, which runs a postinstall script during npm install to collect and exfiltrate host and environment information. The exfiltrated data includes hostname, username, platform, Node.js version, non-internal IP addresses, registry URL, and the full process environment variables, potentially exposing sensitive secrets such as AWS keys and tokens. The data is sent to an attacker-controlled Feishu/Lark bot webhook URL, which is obfuscated using character code transformations and XOR encoding. The malware employs extensive anti-analysis checks, including detection of honeypot tokens, sandbox environment variables, CI environment indicators, and suspicious hostnames or usernames, to avoid execution in analysis environments. The obfuscation and anti-analysis measures are designed to evade casual review and automated detection.
Potential Impact
The malware can lead to the exposure of sensitive environment variables and secrets, including tokens and AWS keys, from developer and CI environments. This exposure can result in unauthorized access to cloud resources, data breaches, and further compromise of development and deployment pipelines. The stealthy exfiltration and anti-analysis features increase the likelihood of prolonged undetected presence in affected environments.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. Users should immediately remove @longzy/react-native-polyfill from their projects and audit their environment for potential secret exposure. Rotate any potentially compromised secrets such as tokens and AWS keys. Avoid installing packages from untrusted sources and monitor dependency trees for suspicious or unknown packages. Since this is a malicious package rather than a vulnerability in legitimate software, remediation involves removal and secret rotation rather than patching.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6597
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a42ed8127e9c79719946fe7
Added to database: 06/29/2026, 22:11:13 UTC
Last enriched: 06/29/2026, 22:45:26 UTC
Last updated: 06/30/2026, 00:56:01 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.