VYPR

npm · Malicious package advisory

Malware

@channel_bot/xa0

MAL-2026-3336

Malicious code in @channel_bot/xa0 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (af511b868a0f1a7152f2b73076b3741da38a5ec9f8b2652af8384ca1890d9372)
The package @channel_bot/xa0 was found to contain malicious code.

## Source: ossf-package-analysis (194976a861d5f77b7bfe921881d36c08ff7ced497269c62b1e55cfa0d63b7dca)
The OpenSSF Package Analysis project identified '@channel_bot/xa0' @ 9.9.99 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

Compromised versions (2)

  • 9.9.99
  • 9.9.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.