VDB
EN

MAL-2026-12078

Malicious code in trezor-lib (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: ossf-package-analysis (d81bc24e9f56c5ca72558e331a2d0fae1d514c1c3fe26d275b5885c91a8a72f5) The OpenSSF Package Analysis project identified 'trezor-lib' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / trezor-lib

No fixed version published yet for trezor-lib (npm). Pin to a known-safe version or switch to an alternative.