npm · Malicious package advisory
Malwarenextiva-dot-com
MAL-2026-1797
Malicious code in nextiva-dot-com (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b526416f0bec682e1493700f926a23b44ef0517c358700e8a9b0025028363f0c) The package nextiva-dot-com was found to contain malicious code.
Compromised versions (1)
- 1.1.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.