npm · Malicious package advisory
Malwaredelphoi
MAL-2026-1998
Malicious code in delphoi (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (72f68bb459a4772a75900ddec7e0a918b514f2211a2303aa80ef82252078e3b6) The package delphoi was found to contain malicious code. ## Source: ossf-package-analysis (c15c8182b6e392861478887a08b04eb8fecc38b70000313dfaf1cad8ac8bc831) The OpenSSF Package Analysis project identified 'delphoi' @ 1.8.2 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 1.8.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.