MAL-2026-2525
Dashboard / Malicious Package / MAL-2026-2525
MAL-2026-2525
Published: 6 Apr 2026Last Modified: 10 Apr 2026
Summary: Malicious code in frontend-backoffice (npm)
Details: Malicious package due to arbitrary command execution, data exfiltration to Telegram, and a suspicious preinstall script executing code on installation. Source: amazon-inspector (2f06949fafe41d4b38a42b1c5573750638b411c02b6edcb1958f3f5aad933d18) The package frontend-backoffice was found to contain malicious code.
Affected packages
Package
Name: frontend-backoffice
Purl: pkg:npm/frontend-backoffice
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
