The same threat actor (UNC3379) hijacked both coa and rc via compromised npm accounts, injecting obfuscated TypeScript post-install scripts that downloaded the DanaBot banking trojan. Neither package had been updated in 3 years before the malicious release. Combined weekly downloads were ~23M; the attack broke React build pipelines globally.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Sonatype (Nexus) | Caught | Nexus Firewall blocks known-malicious packages at ingestion |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |