MAL-2026-1486

    Dashboard / Malicious Package / MAL-2026-1486

    MAL-2026-1486

    Published: 16 Mar 2026Last Modified: 23 Mar 2026

    Summary: Malicious code in trello-enterprises (npm)

    Details: The package is malicious due to a postinstall script executing a file that exfiltrates sensitive information to a remote server. Source: amazon-inspector (9a327d3918cfde33c4405296d7b5e2644bf1435d6532be30af21d41135d529ef) The package trello-enterprises was found to contain malicious code.

    Affected packages

    Package

    Name: trello-enterprises

    Purl: pkg:npm/trello-enterprises

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2026-1486 | CVE-DB