VYPR

npm · Malicious package advisory

Malware

airbnb-react-router-legacy

MAL-2025-190604

Malicious code in airbnb-react-router-legacy (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (dbad26f42924fe90947efc559b87354b3cc495e2aad542844029ebfe7d0ec3d9)
The package airbnb-react-router-legacy was found to contain malicious code.

## Source: ossf-package-analysis (1b1138ad535181a63df363ed1d9c8c20e762dc5a528a57b098494d878b61a837)
The OpenSSF Package Analysis project identified 'airbnb-react-router-legacy' @ 97.1.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 97.1.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.