—
MAL-2025-68
Malicious code in kiota-typescript (npm)
Details
This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.
--- _-= Per source details. Do not edit below this line.=-_
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/kiota-typescript
No fixed version published yet for kiota-typescript (npm). Pin to a known-safe version or switch to an alternative.