@spx-delivery/react
MAL-2026-261
npmmalware1/16/2026
Description
Malicious code in @spx-delivery/react (npm)
Indicators of Compromise
SHA256 Hashes (3)
b03f32e2859ef16f71897fc985589e436c704979df087b57bb61fedb63e89c51
4c3aa1b060dff87d257c88e0db2903a7c1c6e618460a5a5e93c68eaac59a9645
81f515c184c8adb38d36334b51d2e0f38c1c1e839bf927858e34900125ffec2f
References (1)
Details
Ecosystemnpm
Attack Typemalware
Published1/16/2026
Affected Versions
0
Aliases
GHSA-vwcv-3mcr-rq5q
Quick Actions