npm · Malicious package advisory
Malwaretest-on-other-again
MAL-2026-491
Malicious code in test-on-other-again (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (0c2b4e18e26bfe221e4ebcdaa18a271ea746bee1977c35172726fd753a923897) The package test-on-other-again was found to contain malicious code. ## Source: ossf-package-analysis (558a211dc43b6520b3337975ab954f89ca97679707396cd9dcf19a8a0853b647) The OpenSSF Package Analysis project identified 'test-on-other-again' @ 99.9.8 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Compromised versions (1)
- 99.9.8
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.