npm · Malicious package advisory
Malwarevinext-monorepo
MAL-2026-2861
Malicious code in vinext-monorepo (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b5c7279d5c84c989a0deef7944c5d1d22b89651bdc01da8fc5144622a8fc74cb) The package vinext-monorepo was found to contain malicious code. ## Source: ossf-package-analysis (574f240251e7be8dcdf3c0b77c1df87b69497f67e98d64b831a36ab87c2d08de) The OpenSSF Package Analysis project identified 'vinext-monorepo' @ 99.10.9 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (3)
- 99.10.9
- 99.9.9
- 99.12.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.