VYPR

npm · Malicious package advisory

Malware

@immuta/flag-providers-web

MAL-2026-1382

Malicious code in @immuta/flag-providers-web (npm)

Details

Malicious package due to data exfiltration, command execution, and suspicious install scripts. Gathers system info and sends it to a remote server.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (041967637fd096ee4ba0091769b628c2c7da4bd4a60f38a6b4e3ba5cea9cf788)
The package @immuta/flag-providers-web was found to contain malicious code.