npm · Malicious package advisory
Malwareunisys-agentic-ai-playground
MAL-2026-2874
Malicious code in unisys-agentic-ai-playground (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (13ec6c43f5a186c6e78aca52041174240070088e17078f1bcb9f63ac0d55f5f0) The package unisys-agentic-ai-playground was found to contain malicious code. ## Source: ossf-package-analysis (b3c6ad275dea5349905eb0d48b04201592c9fb1b7643417f1fed5b63da4c5ac9) The OpenSSF Package Analysis project identified 'unisys-agentic-ai-playground' @ 99.99.2 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Compromised versions (1)
- 99.99.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.