VYPR

npm · Malicious package advisory

Malware

npm_cimetadata

MAL-2026-848

Malicious code in npm_cimetadata (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d1d7a7d39465b33d104fa6608118d45f3077d7a603292dd367135788a47e182d)
The package npm_cimetadata was found to contain malicious code.

## Source: ossf-package-analysis (f7970f24b4e05cac8e0692834347b475d4ab966239b6ad39964ac45802ba49cb)
The OpenSSF Package Analysis project identified 'npm_cimetadata' @ 0.0.1 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (2)

  • 0.0.1
  • 0.0.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.