npm · Malicious package advisory
Malwarefrontend-backoffice
MAL-2026-2525
Malicious code in frontend-backoffice (npm)
Details
Malicious package due to arbitrary command execution, data exfiltration to Telegram, and a suspicious preinstall script executing code on installation. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2f06949fafe41d4b38a42b1c5573750638b411c02b6edcb1958f3f5aad933d18) The package frontend-backoffice was found to contain malicious code.