MAL-2026-2930
Malicious code in path-internal (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (abc4831453df57bac423574143b194320835024fc24fdc838ee77b08db8a4e52) The package path-internal was found to contain malicious code.
## Source: ossf-package-analysis (37a46ea303cb680cff00791b29be183770a5eb1edaef69ce37b97327243deeea) The OpenSSF Package Analysis project identified 'path-internal' @ 1.0.10 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for path-internal (npm). Pin to a known-safe version or switch to an alternative.