Remote Code Execution Vulnerability in React-Tracked by Dai Shi
CVE-2026-48160
What is CVE-2026-48160?
A severe vulnerability in React-Tracked was identified during a specific period in May 2026, where malicious commits were introduced to the default branch. These commits enabled attackers to execute remote code on developer machines through the 'npm install' command. While the malicious code was force-pushed from the repository, local clones, forks, and direct-SHA references may still harbor these commits. The attack targeted developer environments by fetching and executing JavaScript payloads from an attacker-controlled server without proper TLS verification. Users who ran 'npm install' between the specified dates should consider their machines compromised, rotate all accessible credentials, audit account activity from that time, and remove local clones.
Affected Version(s)
react-tracked >= 6978272a7d6ca02225cb747ea69f427512e33699, <= 949f1a3d6bb1ff7d1a0dec892afd773e742627e8
