npm · Malicious package advisory
Malware0xegg2024
MAL-2026-3668
Malicious code in 0xegg2024 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (86f32380998652e4d6d7b70da165cff6d669a4c6a6d9297da2a137071abf6317) Tea.yaml token farming campaign
Compromised versions (1)
- 1.0.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.