VYPR

npm · Malicious package advisory

Malware

frontend-backoffice

MAL-2026-2525

Malicious code in frontend-backoffice (npm)

Details

Malicious package due to arbitrary command execution, data exfiltration to Telegram, and a suspicious preinstall script executing code on installation.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2f06949fafe41d4b38a42b1c5573750638b411c02b6edcb1958f3f5aad933d18)
The package frontend-backoffice was found to contain malicious code.