npm · Malicious package advisory
Malware24712-pl5006
MAL-2026-3362
Malicious code in 24712-pl5006 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d2546cdc76edb1f8a93dcf66c855ca6246bb0d4ed76c72a7fd3c1aec44f34761) The package 24712-pl5006 was found to contain malicious code. ## Source: ossf-package-analysis (115fd80ded696b407b50be96be06645124c2e3c5ca360f283388fcd4bcf3b2de) The OpenSSF Package Analysis project identified '24712-pl5006' @ 0.0.4 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (2)
- 0.0.4
- 0.0.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.