PT-2026-69885 · Npm · Use-Reducer-Async
CVE-2026-48159
·
Published
2026-08-10
·
Updated
2026-08-11
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
use-reducer-async (affected versions not specified)
Description
Malicious commits were introduced into the default branch of the repository, which executed remote attacker-controlled code on developer workstations during the
npm install process. The attack utilized a postinstall script linked to src/install.js to fetch a JavaScript payload from an attacker-controlled HTTPS endpoint, disabled TLS verification, and executed the response using require. The execution was specifically designed to target developer machines, skipping CI and cloud or serverless environments. This allows for full compromise of any resource reachable from a Node process with the user's permissions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Clean all local clones of the repository.
Rotate every credential reachable from the affected machine.
Audit account activity since 2026-05-18 16:29:52.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Use-Reducer-Async