VDB
Sign up

MAL-2026-15868

Malicious code in @bx-ui-framework/microfrontend (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e1680cbcfbae85350989b4d123a117deb73e45aad1ee7aa339cdcef34d3fbe30) package.json declares a runtime dependency `microfrontend` whose source is a bare HTTPS URL at `https://repo.artifactorymanager.com/bx-ui-framework/microfrontend` rather than a version on the npm registry. The URL carries no version, commit, or hash pin, so `npm install` fetches whatever tarball is currently served at that location and executes any lifecycle scripts and code it contains inside the installer's dependency tree. The `artifactorymanager.com` domain is unrelated to any established publisher for this scope, and the tarball contents can change at any time without a version bump.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@bx-ui-framework/microfrontend

No fixed version published yet for @bx-ui-framework/microfrontend (npm). Pin to a known-safe version or switch to an alternative.

References