Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in pp-react-worldready (npm)

The npm package pp-react-worldready version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed pp-react-worldready version 1.0.0
Ecosystems
Attack vectors
Affected entities
  • pp-react-worldready · 1.0.0

The OpenSSF Package Analysis project identified pp-react-worldready version 1.0.0 on npm as containing malicious code. The package was flagged for communicating with a domain associated with malicious activity.\n\nThis incident was disclosed on August 1, 2026, and tracked under OpenSSF malicious packages identifier MAL-2026-11427. The malicious package was published to the npm registry and could affect any user who installed this specific version.

Indicators of compromise

Packages
  • pp-react-worldready@1.0.0

Remediation

  • Remove pp-react-worldready version 1.0.0 from all environments
  • Audit systems where this package was installed for signs of compromise
  • Check for any outbound connections to the malicious domain associated with this package
  • Review package.json and lock files to identify affected installations
  • Use npm audit to identify if this package is present in your dependency tree

Sources

  1. GitHub Advisory GHSA-4g95-5h46-4643 · GitHub Advisory Database

Cite this entry

"Malicious code in pp-react-worldready (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 1, 2026; last updated August 1, 2026. https://supplychainattack.org/incident/malicious-code-in-pp-react-worldready-npm-1w0f6r

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malware in @moxfive-llc/common

    Malware was discovered in the npm package @moxfive-llc/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2. resolvedcritical

    Malware in test-dev-dispatch

    Malware was discovered in the npm package test-dev-dispatch. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  3. containedcritical

    Malware in test-dev-store

    Malware was discovered in the npm package test-dev-store. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  4. resolvedcritical

    Malware in test-dev-watch

    Malware was discovered in the npm package test-dev-watch, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package