Malicious code in iconova-react (npm)
The npm package iconova-react (versions 1.30.0 and 1.30.1) is a malicious re-hosted copy of lucide-react containing injected code in two icon modules. This code executes at import time, querying Ethereum blockchain data to retrieve IP addresses for fetching and executing attacker-controlled payloads, enabling arbitrary code execution on the host system. This is a deliberate supply-chain attack exploiting the package's impersonation of lucide-react.
AI Analysis
Technical Summary
iconova-react is a malicious npm package impersonating lucide-react, with injected asynchronous code in the sparkle and sparkles icon modules. Upon import, the code queries public Ethereum RPC endpoints for the latest transaction from a hardcoded attacker address, extracts IP addresses from the transaction data, and downloads encoded secondary payloads from these IPs. These payloads are decoded and executed via eval and detached Node.js processes, allowing arbitrary code execution on the installer's or build server's host. The use of on-chain dead-drop resolution, unicode-escaped strings, and package impersonation confirms this as a deliberate supply-chain attack rather than an accidental vulnerability.
Potential Impact
Importing iconova-react or its sparkle/sparkles icons triggers execution of attacker-controlled code on the host system, potentially compromising build servers or developer machines. This can lead to full system compromise, data theft, or further malware deployment. The attack leverages blockchain data for dynamic payload retrieval, making detection and mitigation more complex.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using iconova-react versions 1.30.0 and 1.30.1. Replace the package with the legitimate lucide-react package or verified sources. Conduct thorough audits of build environments and developer machines for signs of compromise. Monitor for any unusual network activity related to Ethereum RPC queries or connections to suspicious IP addresses. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Malicious code in iconova-react (npm)
Description
The npm package iconova-react (versions 1.30.0 and 1.30.1) is a malicious re-hosted copy of lucide-react containing injected code in two icon modules. This code executes at import time, querying Ethereum blockchain data to retrieve IP addresses for fetching and executing attacker-controlled payloads, enabling arbitrary code execution on the host system. This is a deliberate supply-chain attack exploiting the package's impersonation of lucide-react.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
iconova-react is a malicious npm package impersonating lucide-react, with injected asynchronous code in the sparkle and sparkles icon modules. Upon import, the code queries public Ethereum RPC endpoints for the latest transaction from a hardcoded attacker address, extracts IP addresses from the transaction data, and downloads encoded secondary payloads from these IPs. These payloads are decoded and executed via eval and detached Node.js processes, allowing arbitrary code execution on the installer's or build server's host. The use of on-chain dead-drop resolution, unicode-escaped strings, and package impersonation confirms this as a deliberate supply-chain attack rather than an accidental vulnerability.
Potential Impact
Importing iconova-react or its sparkle/sparkles icons triggers execution of attacker-controlled code on the host system, potentially compromising build servers or developer machines. This can lead to full system compromise, data theft, or further malware deployment. The attack leverages blockchain data for dynamic payload retrieval, making detection and mitigation more complex.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using iconova-react versions 1.30.0 and 1.30.1. Replace the package with the legitimate lucide-react package or verified sources. Conduct thorough audits of build environments and developer machines for signs of compromise. Monitor for any unusual network activity related to Ethereum RPC queries or connections to suspicious IP addresses. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13705
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a79f0c4bf8831d539f5dc7f
Added to database: 08/10/2026, 15:39:48 UTC
Last enriched: 08/10/2026, 15:41:44 UTC
Last updated: 08/10/2026, 15:42:20 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.