react-paginate-v5@99.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC
OSV ID
MAL-2026-17777
Ecosystem
npm
Summary
react-paginate-v5@99.0.0 is a dependency-confusion probe published under a name resembling the popular react-paginate package and pinned to an implausibly high version (99.0.0) to win resolution against an internal package. Its package.json declares a preinstall lifecycle script that runs nslookup dep-confusion-poc.2chsn9exkdupkr3cxed7vp7sk.canarytokens.com, which fires automatically on npm install and emits a DNS query from the installer's resolver to an attacker/researcher-controlled canary subdomain. The subdomain label (dep-confusion-poc) self-identifies the operation as a dependency-confusion test. The DNS lookup confirms successful installation to the operator of the canary token, identifying hosts and networks where an internal package name was shadowed by this public squat. While the beacon itself only exfiltrates the fact of installation plus resolver metadata, the same install-time execution primitive can carry any shell command, and the package has no legitimate functionality.
Source: amazon-inspector (2c0f91fe35323a6f47033b90ebaf88498a36fd7e8e933711b2cf301dba2e4759)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.