CVE-2026-48161
react18-use Malicious Commits Execute Remote Code on Developer Machines
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
The `react18-use` project's default branch contained malicious commits that could execute remote attacker-controlled code on developer machines during `npm install`. While the malicious commits were removed and the package was not published, local clones or forks of the affected code could still pose a risk, potentiall