react-fontawesome-icons@1.0.6
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-12423
Ecosystem
npm
Summary
The default-exported React component in react-fontawesome-icons@1.0.3 performs an unconditional axios GET to http://command.control on every render and then POSTs document.cookie (together with a static data payload) to http://commad.control/404. Any consumer application that renders this icon component transmits the user's browser session cookies to a hardcoded non-first-party destination. The source uses cover-story naming and comments (not_ma_li_ci_ous_at_all, 'nothing harmful here LOL') and a commented base64 flag-decoder around the exfiltration call, indicating deliberate misdirection rather than accident. The package is presented as a Font Awesome icon component; icon rendering does not require any outbound network traffic, and the destination hosts are not resolvable legitimate infrastructure.
Source: amazon-inspector (4706d295cdd6ae07918ab25d54475d97d88e92c8ba2d3923078ba916096b4366)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.