VYPR

npm · Malicious package advisory

Malware

@thiagoemmanuell/unhandledrejection

MAL-2026-2081

Malicious code in @thiagoemmanuell/unhandledrejection (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6c7b0d7b4bc457f62d681b55f8cd95c7759ad36fd6565ff2e3e0dd95a0faca97)
The package @thiagoemmanuell/unhandledrejection was found to contain malicious code.

## Source: ossf-package-analysis (5ac41fed5a1a3457deca490f1b90216ef63d1263f041fcee111c14eddb777efd)
The OpenSSF Package Analysis project identified '@thiagoemmanuell/unhandledrejection' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.