Malicious code in fr-ito-web-react (npm)
The npm package fr-ito-web-react version 99.99.99 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
- Disclosed
- Last updated
- Blast radius
- All users of fr-ito-web-react version 99.99.99
- Ecosystems
- Attack vectors
- Affected entities
- fr-ito-web-react · 99.99.99
The OpenSSF Package Analysis project identified fr-ito-web-react version 99.99.99 on npm as containing malicious code. Analysis revealed that the package communicates with a domain associated with malicious activity and executes one or more commands associated with malicious behavior.\n\nThe malicious package was cataloged in the OpenSSF's malicious-packages repository (MAL-2026-14019). This indicates the package was likely published with intentional malicious intent rather than being a legitimate package that was subsequently compromised.\n\nAny system that installed this specific version of fr-ito-web-react is potentially affected and should be considered compromised.
Indicators of compromise
- Packages
- fr-ito-web-react@99.99.99
Remediation
- Immediately remove fr-ito-web-react version 99.99.99 from all systems and projects
- Audit all systems where this package was installed for signs of compromise or unauthorized activity
- Review and rotate any credentials or secrets that may have been exposed on affected systems
- Check npm audit logs and dependency trees to identify all affected projects
- Consider using alternative packages for the intended functionality
- Monitor affected systems for suspicious network connections or command execution
Sources
- GitHub Advisory GHSA-rqvx-rm83-r9wh · GitHub Advisory Database
Cite this entry
"Malicious code in fr-ito-web-react (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-fr-ito-web-react-npm-1uzk4j
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in testingsmthb1g (npm)
The npm package testingsmthb1g contains malicious code in its postinstall script that acts as an install-time dropper, downloading and executing a Windows binary payload and exfiltrating platform information. The attack includes sandbox escape capabilities for WSL/virtualized Linux environments.
npmCompromised package - resolvedcritical
Malicious code in mutex-core (npm)
The npm package mutex-core, published under a name resembling the popular async-mutex library, contained malicious code including a staged loader that decrypts and executes hidden payloads. The package included obfuscated code that conditionally triggers AES-256-GCM decryption and execution of encrypted binary content when specific conditions are met.
npmCompromised package - containedcritical
Malicious code in tyepescript-cli (npm)
tyepescript-cli, a typosquat of the legitimate typescript package on npm, contains malicious postinstall code that downloads and executes a Windows binary (main.exe) and beacons to an attacker-controlled server. The package uses XOR obfuscation to hide URLs, commands, and IP addresses, with special logic to target both Windows and WSL environments.
npmTyposquattingCompromised package - containedcritical
Malicious code in commandor-cli (npm)
commandor-cli@1.0.0 on npm contains malicious postinstall script that downloads and executes a binary from an attacker-controlled GitHub repository. The script also beacons installation metadata to a command-and-control server and includes a PowerShell bridge to extend execution to Windows hosts on WSL systems.
npmCompromised packageMalicious commit