VYPR

npm · Malicious package advisory

Malware

@immuta/pxl-components

MAL-2026-1383

Malicious code in @immuta/pxl-components (npm)

Details

Malicious package due to data exfiltration, arbitrary command execution, and suspicious install scripts targeting dependency confusion.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (03d86f67d7f931d0f720838a4bda33d56a54a5502b29ebe3e1094a984041b7a2)
The package @immuta/pxl-components was found to contain malicious code.