npm · Malicious package advisory
Malwareuser_migration
MAL-2026-1872
Malicious code in user_migration (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6a952d55363362a942ec86eee421ffd30f1de7fbc2e9575ea1a37eaae9a73603) The package user_migration was found to contain malicious code.
Compromised versions (1)
- 9.99.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.