Malicious code in react-wp-viewer (npm)
The npm package react-wp-viewer versions 0.2.4, 0.2.15, and 0.2.99 is a dependency-confusion malicious package. Its postinstall script makes an HTTP request to an attacker-controlled IP, leaking environment details such as the installer's IP and hostname. This behavior indicates it is squatting on an internal package name to gather reconnaissance data. The package may lead to full system compromise, and any secrets on affected systems should be rotated immediately.
AI Analysis
Technical Summary
The react-wp-viewer npm package in versions 0.2.4, 0.2.15, and 0.2.99 is identified as a dependency-confusion malicious package. Upon installation, its postinstall hook performs an HTTP GET request to a hardcoded attacker-controlled IP address, transmitting the package name, version, and a fixed nonce. This request leaks the installer's source IP, hostname-derived network position, and confirms the presence of an internal package namespace with the same name. The package self-identifies as a dependency-confusion proof-of-concept and is designed to squat on an internal package name to win resolution against a private package. Although no installer credentials are directly accessed, the callout provides valuable reconnaissance data to attackers. According to a malware source, any system with this package installed or running should be considered fully compromised, and all secrets and keys must be rotated. Removal of the package alone may not eliminate all malicious software introduced.
Potential Impact
The package leaks sensitive environment information to an attacker-controlled server during installation, which can be used for reconnaissance. The malware source warns that systems with this package installed should be considered fully compromised, implying potential unauthorized control and data exposure. Secrets and keys stored on affected systems are at risk and require immediate rotation. The package's presence indicates a successful dependency-confusion attack, which can undermine supply chain security.
Mitigation Recommendations
No official patch or remediation is provided. Users should immediately remove the react-wp-viewer package versions 0.2.4, 0.2.15, and 0.2.99 from their environments. All secrets and keys on affected systems should be rotated from a secure, uncompromised environment. Due to the potential full compromise, a thorough system audit and possible rebuild are recommended. Monitor for any signs of persistent malicious activity beyond the package removal.
Malicious code in react-wp-viewer (npm)
Description
The npm package react-wp-viewer versions 0.2.4, 0.2.15, and 0.2.99 is a dependency-confusion malicious package. Its postinstall script makes an HTTP request to an attacker-controlled IP, leaking environment details such as the installer's IP and hostname. This behavior indicates it is squatting on an internal package name to gather reconnaissance data. The package may lead to full system compromise, and any secrets on affected systems should be rotated immediately.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The react-wp-viewer npm package in versions 0.2.4, 0.2.15, and 0.2.99 is identified as a dependency-confusion malicious package. Upon installation, its postinstall hook performs an HTTP GET request to a hardcoded attacker-controlled IP address, transmitting the package name, version, and a fixed nonce. This request leaks the installer's source IP, hostname-derived network position, and confirms the presence of an internal package namespace with the same name. The package self-identifies as a dependency-confusion proof-of-concept and is designed to squat on an internal package name to win resolution against a private package. Although no installer credentials are directly accessed, the callout provides valuable reconnaissance data to attackers. According to a malware source, any system with this package installed or running should be considered fully compromised, and all secrets and keys must be rotated. Removal of the package alone may not eliminate all malicious software introduced.
Potential Impact
The package leaks sensitive environment information to an attacker-controlled server during installation, which can be used for reconnaissance. The malware source warns that systems with this package installed should be considered fully compromised, implying potential unauthorized control and data exposure. Secrets and keys stored on affected systems are at risk and require immediate rotation. The package's presence indicates a successful dependency-confusion attack, which can undermine supply chain security.
Defensive Guidance
No official patch or remediation is provided. Users should immediately remove the react-wp-viewer package versions 0.2.4, 0.2.15, and 0.2.99 from their environments. All secrets and keys on affected systems should be rotated from a secure, uncompromised environment. Due to the potential full compromise, a thorough system audit and possible rebuild are recommended. Monitor for any signs of persistent malicious activity beyond the package removal.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6571
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a42ed7827e9c797199395c1
Added to database: 06/29/2026, 22:11:04 UTC
Last enriched: 08/21/2026, 16:28:57 UTC
Last updated: 09/14/2026, 18:14:48 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.