npm · Malicious package advisory
Malwarereact-query-core-utils
MAL-2026-1837
Malicious code in react-query-core-utils (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3bce94f40a0e1879b184cd9f5abb5f4850d66aa5705b231b41337c2e2e33a3de) The package react-query-core-utils was found to contain malicious code.
Compromised versions (12)
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.7
- 4.4.8
- 4.4.9
- 4.5.1
- 4.5.2
- 4.5.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.