VYPR

npm · Malicious package advisory

Malware

@bingads-webui-component-legacy/storage

MAL-2026-127

Malicious code in @bingads-webui-component-legacy/storage (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b1b0ef4dc1d3bac0f76b00b2134e0e39c61034e61e307a6390e8c92dacad80c2)
The package @bingads-webui-component-legacy/storage was found to contain malicious code.

## Source: ossf-package-analysis (ca5cab7ae6e72da40ce41754bd8420123f07157eb86bb9c3b6232a9802a6a7bc)
The OpenSSF Package Analysis project identified '@bingads-webui-component-legacy/storage' @ 99.9.9 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 99.9.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.