Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in iconova-react (npm)

0
Critical
Published: 08/10/2026 (08/10/2026, 12:25:20 UTC)
Source: GCVE Database
Product: iconova-react

Description

The npm package iconova-react (versions 1.30.0 and 1.30.1) is a malicious re-hosted copy of lucide-react containing injected code in two icon modules. This code executes at import time, querying Ethereum blockchain data to retrieve IP addresses for fetching and executing attacker-controlled payloads, enabling arbitrary code execution on the host system. This is a deliberate supply-chain attack exploiting the package's impersonation of lucide-react.

Affected software

npmghsa
iconova-react
Affected versions
=1.30.0=1.30.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 15:41:44 UTC

Technical Analysis

iconova-react is a malicious npm package impersonating lucide-react, with injected asynchronous code in the sparkle and sparkles icon modules. Upon import, the code queries public Ethereum RPC endpoints for the latest transaction from a hardcoded attacker address, extracts IP addresses from the transaction data, and downloads encoded secondary payloads from these IPs. These payloads are decoded and executed via eval and detached Node.js processes, allowing arbitrary code execution on the installer's or build server's host. The use of on-chain dead-drop resolution, unicode-escaped strings, and package impersonation confirms this as a deliberate supply-chain attack rather than an accidental vulnerability.

Potential Impact

Importing iconova-react or its sparkle/sparkles icons triggers execution of attacker-controlled code on the host system, potentially compromising build servers or developer machines. This can lead to full system compromise, data theft, or further malware deployment. The attack leverages blockchain data for dynamic payload retrieval, making detection and mitigation more complex.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately stop using iconova-react versions 1.30.0 and 1.30.1. Replace the package with the legitimate lucide-react package or verified sources. Conduct thorough audits of build environments and developer machines for signs of compromise. Monitor for any unusual network activity related to Ethereum RPC queries or connections to suspicious IP addresses. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13705
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a79f0c4bf8831d539f5dc7f

Added to database: 08/10/2026, 15:39:48 UTC

Last enriched: 08/10/2026, 15:41:44 UTC

Last updated: 08/10/2026, 15:42:20 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses