SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration via Discord webhook on install. Collects IP, hostname, and date without consent.

Verification Record

The package is marked as malware by OSV: MAL-2026-1040 with source: ossf-package-analysis

Details

Note: This report is updated by a verification record

The package react-markdown-canvas version 1007.0.0 contains malicious code in the scripts/after-install.js file. This script is executed automatically after installation via the postinstall script in package.json. The script retrieves the user's IP address, hostname, and current date and sends this information to a Discord webhook. This constitutes data exfiltration without the user's consent or knowledge and is a strong indicator of malicious intent. Multiple YARA rules and LLM-based analysis confirm the presence of a Discord webhook URL, IP address retrieval, data exfiltration, and automatic execution on install.

react-markdown-canvas@1007.0.0Malicious
Verified
Analysed at: 2/23/26, 10:21 PM
Source: https://registry.npmjs.org/react-markdown-canvas/-/react-markdown-canvas-1007.0.0.tgz
SHA256: ea2ae62d5b9e2be05184305f81bc000a18f102e222fa0ceabde3bfba9eeb2055
Confidence: High