npm · Malicious package advisory
Malwarebfx-hf-strategy-perf
MAL-2026-2696
Malicious code in bfx-hf-strategy-perf (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (aac057221646f5043eab6606ba990a3a112afc149c583347e40321643deab7ba) The package bfx-hf-strategy-perf was found to contain malicious code. ## Source: ossf-package-analysis (4db2d68b59a3e893535f6b9163042c33e8f236cb4b6df4132493042b7afdf0df) The OpenSSF Package Analysis project identified 'bfx-hf-strategy-perf' @ 1000.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Compromised versions (1)
- 1000.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.