VYPR

npm · Malicious package advisory

Malware

ing-feat-mortgage-consent-starter

MAL-2025-192935

Malicious code in ing-feat-mortgage-consent-starter (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (626d72f10b630f53b78e042906e6724ca662099bfc31e82310575ea19452576f)
The package ing-feat-mortgage-consent-starter was found to contain malicious code.

## Source: ossf-package-analysis (1afe25b50bb9c4fb8cf4338ff4c2088058cafa2cebd36e5ca18b5348bee6d6e4)
The OpenSSF Package Analysis project identified 'ing-feat-mortgage-consent-starter' @ 99.99.99 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (1)

  • 99.99.99

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.