MAL-2026-2418

    Dashboard / Malicious Package / MAL-2026-2418

    MAL-2026-2418

    Published: 24 Mar 2026Last Modified: 7 Apr 2026

    Summary: Malicious code in tombac-chronos (npm)

    Details: Suspicious install script executing `index.js` and an untrustworthy author email domain `sl4x0.xyz` strongly suggest this package is malware. Source: amazon-inspector (69e040ef4bdedbed143a5a8d1a1bb0389fa07848772a87c03da1c67557ced13e) The package tombac-chronos was found to contain malicious code.

    Affected packages

    Package

    Name: tombac-chronos

    Purl: pkg:npm/tombac-chronos

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2026-2418 | CVE-DB