MAL-2026-1229

    Dashboard / Malicious Package / MAL-2026-1229

    MAL-2026-1229

    Published: 25 Feb 2026Last Modified: 8 Mar 2026

    Summary: Malicious code in @schedaero/net-common (npm)

    Details: Malicious package due to suspicious preinstall script, data exfiltration via User-Agent, process termination, and a suspicious URL. Source: amazon-inspector (2e5e87e24ed2574837f59c3fb4cf21d0c9677b4d5e729f0835fc90a9bf427c4c) The package @schedaero/net-common was found to contain malicious code.

    Affected packages

    Package

    Name: @schedaero/net-common

    Purl: pkg:npm/%40schedaero/net-common

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions