npm · Malicious package advisory
Malwareaoflmkt
MAL-2026-3614
Malicious code in aoflmkt (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ossf-package-analysis (7d5581b164c03c1b17ecfa5e7bab0422b7168cb3a8d44108ac108467e37adbc2) The OpenSSF Package Analysis project identified 'aoflmkt' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.