npm · Malicious package advisory
Malware@gr-exports/async
MAL-2025-191560
Malicious code in @gr-exports/async (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b8832eae90b7d3651b42c92dfd4d5c51fa5766d1e571fab494f073a6389b3aa1) The package @gr-exports/async was found to contain malicious code.
Compromised versions (2)
- 1.0.0
- 99.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.