Malicious code in @espn-ping/react-dmed-oauth (npm)
MAL-2026-10401 · GHSA-c99m-x4q9-727p
Published · Modified
Dependency scanning
Check whether @espn-ping/react-dmed-oauth is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (3bc0467ac62043cf22dd249a99ff1279646dc599702140998ff5b86c79645364)
@espn-ping/react-dmed-oauth@666.0.0 declares a preinstall lifecycle script (node index.js > /dev/null 2>&1) that automatically executes on npm install. index.js shells out via child_process.exec to collect the installer's hostname, current working directory, username, and public IP (via curl https://ifconfig.me), then transmits the encoded data via curl -k GET to https://r.dontvisitmy.website/sendreq.php?newdata=.... Output is suppressed to hide the beacon from the installer's console. The scope @espn-ping and version 666.0.0 are consistent with a dependency-confusion beacon targeting an internal ESPN/Disney namespace.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes