MAL-2026-11144
Malicious code in react-puller (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a3ac07c0f6c79714a7b1f6bfd1272f9f7942cf0473875ca5276a1034c084f06d) The package's postinstall hook runs `node index.js`, which spawns a detached worker that downloads two Windows executables (CDPUserPlatform.exe and DOContentCacheMgr.exe) from a hardcoded bare-IP endpoint at http://64.49.11.161:8000 over plain HTTP, writes them into `~/.react-pul`, and launches them via `cmd /c start`. The `addToStartup` routine then writes an HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry pointing at `~/.react-pul/DOContentCacheMgr.exe`, autostarting the dropped binary on every user login. The package name and description present it as a generic React utility, unrelated to the shipped behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for react-puller (npm). Pin to a known-safe version or switch to an alternative.