VYPR

npm · Malicious package advisory

Malware

@mimecast-ui/charts

MAL-2026-3506

Malicious code in @mimecast-ui/charts (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e603deff481f2fdd492adde6f7d1f060fa7aa7d15f63abc4cc43fa7782409705)
The package @mimecast-ui/charts was found to contain malicious code.

## Source: ossf-package-analysis (831be2c3e6c9885c479ff2920f4f2bd45a313483073af42ed59ba0ac78a98e3b)
The OpenSSF Package Analysis project identified '@mimecast-ui/charts' @ 2.0.0 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

Compromised versions (1)

  • 2.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.