MAL-2026-2716

    Dashboard / Malicious Package / MAL-2026-2716

    MAL-2026-2716

    Published: 5 Apr 2026Last Modified: 23 Apr 2026

    Summary: Malicious code in @needl-ai/common (npm)

    Details: Source: amazon-inspector (e1b98ae2755d0fd7d61bc3dfd378dc1bad2eadf7ef0033ba66bbf1383a711e5c) The package @needl-ai/common was found to contain malicious code. Source: ossf-package-analysis (7eced6745ccb1cab99a3bf2df80ebdb76fa0d0275f88c1956dce1194b94a088e) The OpenSSF Package Analysis project identified '@needl-ai/common' @ 99.99.2 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: @needl-ai/common

    Purl: pkg:npm/%40needl-ai/common

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-2716 | CVE-DB