MAL-2026-1382

    Dashboard / Malicious Package / MAL-2026-1382

    MAL-2026-1382

    Published: 13 Mar 2026Last Modified: 23 Mar 2026

    Summary: Malicious code in @immuta/flag-providers-web (npm)

    Details: Malicious package due to data exfiltration, command execution, and suspicious install scripts. Gathers system info and sends it to a remote server. Source: amazon-inspector (041967637fd096ee4ba0091769b628c2c7da4bd4a60f38a6b4e3ba5cea9cf788) The package @immuta/flag-providers-web was found to contain malicious code.

    Affected packages

    Package

    Name: @immuta/flag-providers-web

    Purl: pkg:npm/%40immuta/flag-providers-web

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2026-1382 | CVE-DB