MAL-2026-15868
Dashboard / Malicious Package / MAL-2026-15868
MAL-2026-15868
Summary: Malicious code in @bx-ui-framework/microfrontend (npm)
Details: Source: amazon-inspector (e1680cbcfbae85350989b4d123a117deb73e45aad1ee7aa339cdcef34d3fbe30) package.json declares a runtime dependency `microfrontend` whose source is a bare HTTPS URL at `https://repo.artifactorymanager.com/bx-ui-framework/microfrontend` rather than a version on the npm registry. The URL carries no version, commit, or hash pin, so `npm install` fetches whatever tarball is currently served at that location and executes any lifecycle scripts and code it contains inside the installer's dependency tree. The `artifactorymanager.com` domain is unrelated to any established publisher for this scope, and the tarball contents can change at any time without a version bump.
Affected packages
Package
Name: @bx-ui-framework/microfrontend
Purl: pkg:npm/%40bx-ui-framework/microfrontend
Affected ranges
Type: N/A
Events:
