Malicious code in pp-react-worldready (npm)
The npm package pp-react-worldready version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
- Disclosed
- Last updated
- Blast radius
- All users who installed pp-react-worldready version 1.0.0
- Ecosystems
- Attack vectors
- Affected entities
- pp-react-worldready · 1.0.0
The OpenSSF Package Analysis project identified pp-react-worldready version 1.0.0 on npm as containing malicious code. The package was flagged for communicating with a domain associated with malicious activity.\n\nThis incident was disclosed on August 1, 2026, and tracked under OpenSSF malicious packages identifier MAL-2026-11427. The malicious package was published to the npm registry and could affect any user who installed this specific version.
Indicators of compromise
- Packages
- pp-react-worldready@1.0.0
Remediation
- Remove pp-react-worldready version 1.0.0 from all environments
- Audit systems where this package was installed for signs of compromise
- Check for any outbound connections to the malicious domain associated with this package
- Review package.json and lock files to identify affected installations
- Use npm audit to identify if this package is present in your dependency tree
Sources
- GitHub Advisory GHSA-4g95-5h46-4643 · GitHub Advisory Database
Cite this entry
"Malicious code in pp-react-worldready (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 1, 2026; last updated August 1, 2026. https://supplychainattack.org/incident/malicious-code-in-pp-react-worldready-npm-1w0f6r
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malware in @moxfive-llc/common
Malware was discovered in the npm package @moxfive-llc/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in test-dev-dispatch
Malware was discovered in the npm package test-dev-dispatch. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - containedcritical
Malware in test-dev-store
Malware was discovered in the npm package test-dev-store. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in test-dev-watch
Malware was discovered in the npm package test-dev-watch, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package