VDB
KO

MAL-2026-1383

Malicious code in @immuta/pxl-components (npm)

Details

Malicious package due to data exfiltration, arbitrary command execution, and suspicious install scripts targeting dependency confusion.

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (03d86f67d7f931d0f720838a4bda33d56a54a5502b29ebe3e1094a984041b7a2) The package @immuta/pxl-components was found to contain malicious code.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @immuta/pxl-components

No fixed version published yet for @immuta/pxl-components (npm). Pin to a known-safe version or switch to an alternative.

References