VYPR

npm · Malicious package advisory

Malware

@schedaero/yukon

MAL-2026-1232

Malicious code in @schedaero/yukon (npm)

Details

Multiple evidences indicate malicious behavior: suspicious URL, data exfiltration, process exiting, and preinstall script execution.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b02868b7ba4a5e5bf754e692e348191e6974f2f707417f20f97b33f172cda4ca)
The package @schedaero/yukon was found to contain malicious code.