npm · Malicious package advisory
Malwaremms-thin-client
GHSA-557c-973f-xg6r
Malicious code in mms-thin-client (npm)
Details
**Severity:** Critical **Affected versions:** `= 0.0.1-security` ## Source: amazon-inspector (57427ccebae288ec20571b2713f7e71b7cf97044e30896db254f9371e32764f3) The package mms-thin-client was found to contain malicious code. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/69aefe746e04eebf6da81a0607bae7ad381c7e4c/osv/malicious/npm/mms-thin-client/MAL-2025-49231.json)) **References:** - https://github.com/ossf/malicious-packages/blob/69aefe746e04eebf6da81a0607bae7ad381c7e4c/osv/malicious/npm/mms-thin-client/MAL-2025-49231.json - https://github.com/advisories/GHSA-557c-973f-xg6r
Compromised versions (1)
- = 0.0.1-security
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.