npm · Malicious package advisory
Malwareupdate-db
MAL-2026-3315
Malicious code in update-db (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (9b606e43d802d06fa7b5d14f020e7727886462320dd05dca09c16887b15d5a37) The package update-db was found to contain malicious code. ## Source: ossf-package-analysis (188c4543894354956bdb0ef341ed98247a992c1ab7a8873fa6ac1c7533e9b1c0) The OpenSSF Package Analysis project identified 'update-db' @ 99.1.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (2)
- 99.1.0
- 99.1.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.