Skip to main content

Malicious code in react-wp-viewer (npm)

0
Medium
Published: 06/29/2026 (06/29/2026, 04:17:26 UTC)
Source: GCVE Database
Product: react-wp-viewer

Description

The npm package react-wp-viewer versions 0.2.4, 0.2.15, and 0.2.99 is a dependency-confusion malicious package. Its postinstall script makes an HTTP request to an attacker-controlled IP, leaking environment details such as the installer's IP and hostname. This behavior indicates it is squatting on an internal package name to gather reconnaissance data. The package may lead to full system compromise, and any secrets on affected systems should be rotated immediately.

Affected software

npmghsa
react-wp-viewer
Affected versions
=0.2.15=0.2.4=0.2.99

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 16:28:57 UTC

Technical Analysis

The react-wp-viewer npm package in versions 0.2.4, 0.2.15, and 0.2.99 is identified as a dependency-confusion malicious package. Upon installation, its postinstall hook performs an HTTP GET request to a hardcoded attacker-controlled IP address, transmitting the package name, version, and a fixed nonce. This request leaks the installer's source IP, hostname-derived network position, and confirms the presence of an internal package namespace with the same name. The package self-identifies as a dependency-confusion proof-of-concept and is designed to squat on an internal package name to win resolution against a private package. Although no installer credentials are directly accessed, the callout provides valuable reconnaissance data to attackers. According to a malware source, any system with this package installed or running should be considered fully compromised, and all secrets and keys must be rotated. Removal of the package alone may not eliminate all malicious software introduced.

Potential Impact

The package leaks sensitive environment information to an attacker-controlled server during installation, which can be used for reconnaissance. The malware source warns that systems with this package installed should be considered fully compromised, implying potential unauthorized control and data exposure. Secrets and keys stored on affected systems are at risk and require immediate rotation. The package's presence indicates a successful dependency-confusion attack, which can undermine supply chain security.

Defensive Guidance

No official patch or remediation is provided. Users should immediately remove the react-wp-viewer package versions 0.2.4, 0.2.15, and 0.2.99 from their environments. All secrets and keys on affected systems should be rotated from a secure, uncompromised environment. Due to the potential full compromise, a thorough system audit and possible rebuild are recommended. Monitor for any signs of persistent malicious activity beyond the package removal.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6571
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a42ed7827e9c797199395c1

Added to database: 06/29/2026, 22:11:04 UTC

Last enriched: 08/21/2026, 16:28:57 UTC

Last updated: 09/14/2026, 18:14:48 UTC

Views: 46

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses