npm · Malicious package advisory
Malware@the-coca-cola-company/ngps-global-common-utils
MAL-2026-2410
Malicious code in @the-coca-cola-company/ngps-global-common-utils (npm)
Details
Malicious post-install script combined with low project popularity indicates potential malware. Arbitrary code execution is a major concern. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3ebe31c5bb51c354ed83627a02c11ca4c8541e042623b1b987255941ffafdaff) The package @the-coca-cola-company/ngps-global-common-utils was found to contain malicious code.
Compromised versions (3)
- 1.0.0
- 9.9.0
- 9.9.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.