npm · Malicious package advisory
Malwareno-use-extend-native
MAL-2025-192825
Malicious code in no-use-extend-native (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6778b114ef0a289408df9f47e2c663640af2fdecb7516d94c9a646c76b75fead) The package no-use-extend-native was found to contain malicious code.
Compromised versions (2)
- 6.9.0
- 6.9.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.