VYPR

npm · Malicious package advisory

Malware

autobahn-electron-probe

GHSA-8jx3-79xq-v4q4

Malicious code in autobahn-electron-probe (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.99.1`

## Source: ossf-package-analysis (d3c07ff64c9729469df8453fb5fd6fa15e1099e81916496d741fe10297e44fc7)
The OpenSSF Package Analysis project identified 'autobahn-electron-probe' @ 99.99.1 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/76323eaa1857e7c8873aa005201b1c9281ac3cdd/osv/malicious/npm/autobahn-electron-probe/MAL-2026-15589.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/76323eaa1857e7c8873aa005201b1c9281ac3cdd/osv/malicious/npm/autobahn-electron-probe/MAL-2026-15589.json
- https://github.com/ossf/malicious-packages/blob/b9c9c442d6f4450955c7f85e197c76604ba12743/osv/malicious/npm/autobahn-electron-probe/MAL-2026-15589.json
- https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.1
- https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.2
- https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.3
- https://github.com/ossf/malicious-packages/blob/672afd706555c110bda936d989979013c03d62f2/osv/malicious/npm/autobahn-electron-probe/MAL-2026-15589.json
- https://github.com/advisories/GHSA-8jx3-79xq-v4q4

Compromised versions (1)

  • = 99.99.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.