react-v17npm
Advisory published Updated
react-v17 is a confirmed malicious npm package (MAL-2026-7020) that typosquats a legitimate package to trick installs (malicious version 20.0.1). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in react-v17 (npm)
What this malware does
Package name 'react-v17' impersonates the legitimate 'react' package. package.json declares a preinstall hook 'node index.js' that auto-executes on npm install. index.js collects installer identity and host details (os.hostname(), os.userInfo(), os.platform/arch, home directory, cwd) and runs 'whoami' and 'id' via child_process.exec, then HTTPS POSTs the aggregate JSON to a hardcoded Burp Collaborator OOB endpoint at https://1jlay7gzya8akcmqs8repdf7oyupim6b.oastify.com/detox56. The tarball also ships an undeclared ~10.9 KB file 'i' next to index.js that is not referenced by package.json or index.js.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for react-v17 (version 20.0.1).
If you installed it — respond
react-v17 is a typosquat — you almost certainly intended a legitimately-named package. Remove react-v17, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If react-v17 was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks react-v17-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.