react-dom-helpers@3.3.3
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC
OSV ID
MAL-2026-14253
Ecosystem
npm
Summary
Package name typosquats react-dom. On require('react-dom-helpers/client'), client.js decodes a base64-obfuscated Slack bot token and channel ID, enumerates local IPv4 addresses via os.networkInterfaces(), fetches the installer's public IP from api.ipify.org, and POSTs the collected host identifiers to https://slack.com/api/chat.postMessage using the hardcoded bearer token. The exfiltration routine is invoked unconditionally at module load. The base64 wrapping of the Slack credential is used to bypass secret scanners.
Source: amazon-inspector (2fae606be0dbd7c79552511c2553ec9e1d081df1279f0bc85502a6c08c0f17fb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.