VYPR

npm · Malicious package advisory

Malware

airbnb-phoenix

MAL-2025-190603

Malicious code in airbnb-phoenix (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9a37ecd19e914e8801e6398f69fea68500fc8c985d6bff3dc5613aaf0ea09692)
The package airbnb-phoenix was found to contain malicious code.

## Source: ossf-package-analysis (dcfe9169befd9818fb7b6849c3b61ef1369e4b8d837d55f779571646ea1e8a6d)
The OpenSSF Package Analysis project identified 'airbnb-phoenix' @ 93.4.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 93.4.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.