MAL-2026-15868
Malicious code in @bx-ui-framework/microfrontend (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (e1680cbcfbae85350989b4d123a117deb73e45aad1ee7aa339cdcef34d3fbe30) package.json declares a runtime dependency `microfrontend` whose source is a bare HTTPS URL at `https://repo.artifactorymanager.com/bx-ui-framework/microfrontend` rather than a version on the npm registry. The URL carries no version, commit, or hash pin, so `npm install` fetches whatever tarball is currently served at that location and executes any lifecycle scripts and code it contains inside the installer's dependency tree. The `artifactorymanager.com` domain is unrelated to any established publisher for this scope, and the tarball contents can change at any time without a version bump.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @bx-ui-framework/microfrontend (npm). Pin to a known-safe version or switch to an alternative.