cvesecurityvulnerability
CVE-2026-48161: react18-use Repository Compromised With Malicious npm install RCE
The react18-use GitHub repository was compromised with malicious commits that executed attacker-controlled code on developer machines during npm install between May 19, 2026. No fixed version exists. Assume full compromise of affected machines.