VDB
KO

MAL-2026-10967

Malicious code in commonweb-moneymovement (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (dee7c2ba53e2c7adae6a2b54776c21490794ee8f28fde98f5c61778380de1382) Package commonweb-moneymovement@99.9.1 contains 2 files with no a static rule matches and no traced behavioral findings. The version number (99.9.1) and name pattern are consistent with an internal or placeholder package rather than a functional library, but no exfiltration, install-time code execution, credential handling, or network callback behavior is present in the shipped contents.

## Source: ossf-package-analysis (84f718c6b68fba15ac3506964439bc33c409cef1390f6cb22fa5a86d074e3a42) The OpenSSF Package Analysis project identified 'commonweb-moneymovement' @ 99.9.1 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / commonweb-moneymovement

No fixed version published yet for commonweb-moneymovement (npm). Pin to a known-safe version or switch to an alternative.

References