Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Package Typosquats react-login-page to Deploy ...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
886
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious npm package named "reeact-login-page" has been identified by the Socket Research team as a typosquatting attack that includes a keylogger to capture keystrokes and exfiltrate sensitive data, such as IP addresses, to a remote server. This package mimics the legitimate "react-login-page" by copying its readme file, logo, and download counts to appear credible while integrating harmful code that discreetly logs and transmits user data. The author, known as lolapalooza, has also published multiple other typosquatted packages targeting React UI components, posing significant security risks for unsuspecting developers. Socket researchers emphasize the importance of thoroughly examining the package name, identifier, and author's previous work to avoid falling victim to such attacks. They recommend using Socket's free GitHub app to automatically analyze and flag potentially malicious packages when new dependencies are added to a project.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.