VYPR

npm · Malicious package advisory

Malware

tombac-chronos

MAL-2026-2418

Malicious code in tombac-chronos (npm)

Details

Suspicious install script executing `index.js` and an untrustworthy author email domain `sl4x0.xyz` strongly suggest this package is malware.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (69e040ef4bdedbed143a5a8d1a1bb0389fa07848772a87c03da1c67557ced13e)
The package tombac-chronos was found to contain malicious code.