VYPR

npm · Malicious package advisory

Malware

@tableau__catalog-messages/database_lower

MAL-2026-2866

Malicious code in @tableau__catalog-messages/database_lower (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4155e0aa6cc429c2ea66b3b131055983379b13cab66b74fa3c1758e83a48ec54)
The package @tableau__catalog-messages/database_lower was found to contain malicious code.

## Source: ossf-package-analysis (d29e8bcb2336d78e40b4d6ff2512beb6286c3426bb33d27a41abdbeb98d59c68)
The OpenSSF Package Analysis project identified '@tableau__catalog-messages/database_lower' @ 99.9.9 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 99.9.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.