MAL-2026-2023
Dashboard / Malicious Package / MAL-2026-2023
MAL-2026-2023
Summary: Malicious code in @mesh-components/customthemeprovider (npm)
Details: Source: amazon-inspector (20b2e29319a8cb96867858b20a43a684624167dc62c186de47de7e7e7e8c8a2a) The package @mesh-components/customthemeprovider was found to contain malicious code. Source: ossf-package-analysis (0ba7699d05c1cb95acd0b80e8a03bc6cb8eb0fa29339f261fe7d5d637ecd7550) The OpenSSF Package Analysis project identified '@mesh-components/customthemeprovider' @ 99999.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
References:
Affected packages
Package
Name: @mesh-components/customthemeprovider
Purl: pkg:npm/%40mesh-components/customthemeprovider
Affected ranges
Type: N/A
Events:
