VYPR

npm · Malicious package advisory

Malware

@schedaero/bacon

MAL-2026-1228

Malicious code in @schedaero/bacon (npm)

Details

Multiple suspicious behaviors: preinstall script exfiltrates data to a suspicious URL, terminates process, and few versions.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e1f79d2ea06bc3905829524120560412e8e875463b5bddeb6bad3a343292c20c)
The package @schedaero/bacon was found to contain malicious code.