Logo
npm

react-fontawesome-icons@1.0.6

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-12423

Ecosystem

npm

Summary

The default-exported React component in react-fontawesome-icons@1.0.3 performs an unconditional axios GET to http://command.control on every render and then POSTs document.cookie (together with a static data payload) to http://commad.control/404. Any consumer application that renders this icon component transmits the user's browser session cookies to a hardcoded non-first-party destination. The source uses cover-story naming and comments (not_ma_li_ci_ous_at_all, 'nothing harmful here LOL') and a commented base64 flag-decoder around the exfiltration call, indicating deliberate misdirection rather than accident. The package is presented as a Font Awesome icon component; icon rendering does not require any outbound network traffic, and the destination hosts are not resolvable legitimate infrastructure.

Source: amazon-inspector (4706d295cdd6ae07918ab25d54475d97d88e92c8ba2d3923078ba916096b4366)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.