VYPR

npm · Malicious package advisory

Malware

24712-pl5006

MAL-2026-3362

Malicious code in 24712-pl5006 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d2546cdc76edb1f8a93dcf66c855ca6246bb0d4ed76c72a7fd3c1aec44f34761)
The package 24712-pl5006 was found to contain malicious code.

## Source: ossf-package-analysis (115fd80ded696b407b50be96be06645124c2e3c5ca360f283388fcd4bcf3b2de)
The OpenSSF Package Analysis project identified '24712-pl5006' @ 0.0.4 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (2)

  • 0.0.4
  • 0.0.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.