VYPR

npm · Malicious package advisory

Malware

conp-dats-editor

MAL-2026-772

Malicious code in conp-dats-editor (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (adac2b3e811707a0113ec1484330ebada12a632966c81143eab49233e87cabbf)
The package conp-dats-editor was found to contain malicious code.

## Source: ossf-package-analysis (5cc3fee45af6f0e407d38408a6aa3f93cdf57db282c56f1b96c216a1fdfc9c74)
The OpenSSF Package Analysis project identified 'conp-dats-editor' @ 999.999.992 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

Compromised versions (4)

  • 999.999.992
  • 999.999.990
  • 999.999.991
  • 999.999.999

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.