Remote Code Execution Vulnerability in use-context-selector by Dai Shi
CVE-2026-48158
What is CVE-2026-48158?
The use-context-selector package from Dai Shi has been compromised through malicious commits that were active between May 18 and May 19, 2026. During this time, the package was manipulated to execute arbitrary code on developer machines upon running npm install. The malicious code, which was cleverly embedded in a script added to the post-install process, fetched a payload from an attacker-controlled endpoint and disabled TLS verification, allowing full compromise of any system components accessible from a Node process with the user's permissions. Though the harmful commits have been removed, developers who cloned or forked the affected repository should consider any installations as potentially compromised, prompting the need for credential rotation, account activity audits, and cleaning of local repositories.
Affected Version(s)
use-context-selector >= 9d8481a513b7b0d1c0941b220c69b25de748641b, <= 6f2dae054ca014068bdbbb4db96006424d674124
