VYPR

npm · Malicious package advisory

Malware

vinext-monorepo

MAL-2026-2861

Malicious code in vinext-monorepo (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b5c7279d5c84c989a0deef7944c5d1d22b89651bdc01da8fc5144622a8fc74cb)
The package vinext-monorepo was found to contain malicious code.

## Source: ossf-package-analysis (574f240251e7be8dcdf3c0b77c1df87b69497f67e98d64b831a36ab87c2d08de)
The OpenSSF Package Analysis project identified 'vinext-monorepo' @ 99.10.9 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (3)

  • 99.10.9
  • 99.9.9
  • 99.12.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.