Malicious code in bui-react-10components (npm)
The npm package bui-react-10components was found to contain malicious code that communicates with a domain associated with malicious activity. The malicious version 99.0.0 was identified by both Amazon Inspector and the OpenSSF Package Analysis project.
- Disclosed
- Last updated
- Blast radius
- All users of bui-react-10components version 99.0.0 and potentially other versions
- Ecosystems
- Attack vectors
- Affected entities
- bui-react-10components · 99.0.0
The npm package bui-react-10components was identified as malicious by multiple security sources. Amazon Inspector and the OpenSSF Package Analysis project both flagged the package as containing malicious code.\n\nVersion 99.0.0 of bui-react-10components was specifically identified as malicious because it communicates with a domain associated with malicious activity. The package was cataloged in the OpenSSF's malicious packages repository (MAL-2026-3804).\n\nThe malicious code appears to have been injected into the package itself, making this a compromised package incident affecting the npm ecosystem.
Indicators of compromise
- Packages
- bui-react-10components@99.0.0
Remediation
- Remove bui-react-10components from all projects immediately
- Audit project dependencies to identify all installations of bui-react-10components
- Review application logs and network traffic for suspicious connections to domains contacted by the malicious package
- Regenerate any credentials or secrets that may have been exposed to systems running the malicious package
- Update to a safe version if one becomes available, or replace the package with a legitimate alternative
- Monitor for any indicators of compromise on systems that ran the malicious package
Sources
- GitHub Advisory GHSA-wfj4-qhgr-q7wq · GitHub Advisory Database
Cite this entry
"Malicious code in bui-react-10components (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-bui-react-10components-npm-1f3jhz
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @vaultflow/update-flow
Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @vaultflow/create-flow
Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malicious code in prettier-lint-lenz (npm)
The npm package prettier-lint-lenz is a malicious imposter of the legitimate Prettier formatter. It executes a postinstall script that deploys clipboard-stealing malware on Windows systems, establishing persistence via a scheduled task that exfiltrates clipboard contents to a hardcoded C2 server.
npmCompromised packageTyposquatting - activecritical
Malware in @wrenfield/viem
The npm package @wrenfield/viem contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package