VYPR

npm · Malicious package advisory

Malware

ac-dom-nodes

MAL-2026-778

Malicious code in ac-dom-nodes (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b323cec1a59645d9dcb2c0951a0f7d31b362ac58e4f930306a940ed67037b20d)
The package ac-dom-nodes was found to contain malicious code.

## Source: ossf-package-analysis (e4ba72c418b98dcfe5864050915ff801c6714ac42005dd039c8823f04231bdd6)
The OpenSSF Package Analysis project identified 'ac-dom-nodes' @ 1.9.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (3)

  • 1.9.0
  • 99.9.9
  • 1.9.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.