MAL-2026-10967
Malicious code in commonweb-moneymovement (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (dee7c2ba53e2c7adae6a2b54776c21490794ee8f28fde98f5c61778380de1382) Package commonweb-moneymovement@99.9.1 contains 2 files with no a static rule matches and no traced behavioral findings. The version number (99.9.1) and name pattern are consistent with an internal or placeholder package rather than a functional library, but no exfiltration, install-time code execution, credential handling, or network callback behavior is present in the shipped contents.
## Source: ossf-package-analysis (84f718c6b68fba15ac3506964439bc33c409cef1390f6cb22fa5a86d074e3a42) The OpenSSF Package Analysis project identified 'commonweb-moneymovement' @ 99.9.1 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for commonweb-moneymovement (npm). Pin to a known-safe version or switch to an alternative.