VYPR

npm · Malicious package advisory

Malware

libxmlussr2

MAL-2025-192394

Malicious code in libxmlussr2 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cef3040d3e54888147d11d2b7de509cbf77a77b93a7d5a6082cb7575d20a6d43)
The package libxmlussr2 was found to contain malicious code.

## Source: ossf-package-analysis (771d953180e5f134a1baec570a2b913442d1541937204f2c3b222e3a056ba688)
The OpenSSF Package Analysis project identified 'libxmlussr2' @ 0.30.2 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 0.30.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.