Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-48161: React 19 Use Hook Shim Malicious Code Execution via Compromised Commits

CVE-2026-48161 · published 1 month ago
Summary

A malicious code was introduced into a React 19 use hook shim through compromised commits, which could execute on developer machines during npm install. If you used this package on or after May 19, 2026, treat your machine as compromised, rotate all credentials, and audit account activity. Update your local clones and remove any affected packages to prevent further issues.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
dai-shi react18-use >= 7b79148d1495a2505f9277da295a98cf176f4496, <= 7b79148d1495a2505f9277da295a98cf176f4496
Original advisory text
react18-use was vulnerable to malicious code execution via compromised commits
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-19 01:07:01 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity since 2026-05-19 01:07:01, and clean local clones.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-506Embedded Malicious Code
Timeline
Published10 Aug 2026
Updated27 Sep 2026
First seen10 Aug 2026
Sources
CVE-2026-48161 · MITRE
Track software like this
Free during beta