npm · Malicious package advisory
Malware@mimecast-ui/charts
MAL-2026-3506
Malicious code in @mimecast-ui/charts (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e603deff481f2fdd492adde6f7d1f060fa7aa7d15f63abc4cc43fa7782409705) The package @mimecast-ui/charts was found to contain malicious code. ## Source: ossf-package-analysis (831be2c3e6c9885c479ff2920f4f2bd45a313483073af42ed59ba0ac78a98e3b) The OpenSSF Package Analysis project identified '@mimecast-ui/charts' @ 2.0.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Compromised versions (1)
- 2.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.