npm · Malicious package advisory
Malwareairbnb-phoenix
MAL-2025-190603
Malicious code in airbnb-phoenix (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (9a37ecd19e914e8801e6398f69fea68500fc8c985d6bff3dc5613aaf0ea09692) The package airbnb-phoenix was found to contain malicious code. ## Source: ossf-package-analysis (dcfe9169befd9818fb7b6849c3b61ef1369e4b8d837d55f779571646ea1e8a6d) The OpenSSF Package Analysis project identified 'airbnb-phoenix' @ 93.4.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 93.4.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.