MAL-2026-14355
Malicious code in fuel-react (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8e35f4772b8cba3555519c250662c67395bf57d89feed3feba7ea067b6bb2c27) The package's postinstall.js script executes automatically on npm install and collects host identity plus environment variables (os.hostname(), process.env) and transmits them via an https request. The package name mimics common React tooling but the shipped install-time behavior is host reconnaissance and environment-variable exfiltration, which frequently captures credentials such as npm tokens, CI secrets, and cloud keys present in process.env.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for fuel-react (npm). Pin to a known-safe version or switch to an alternative.