npm Package for ReExt React Components Library Exfiltrates G...
Blog post from Socket
A research team from Socket has identified a security risk in the npm package for the React ReExt components library, which appears to function as spyware by collecting sensitive developer information, such as operating system usernames, Git usernames, and Git emails, without user consent. This package, which is not officially affiliated with Sencha, surreptitiously reads user Git configuration files and sends the extracted data to a remote server using dynamically generated URLs, raising concerns about unauthorized data exfiltration and potential phishing risks. Despite communication with the package's purported maintainer, Marc Gusmano, who claimed the data collection was experimental and required consent, inconsistencies in his responses and a lack of transparency in the package documentation have heightened suspicion. Although some data collection code was later commented out, the package remains flagged for hidden telemetry, and developers are advised to exercise caution and thoroughly vet any components they incorporate into their projects to avoid inadvertently compromising security.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.