MAL-2026-2954
Dashboard / Malicious Package / MAL-2026-2954
MAL-2026-2954
Published: 20 Apr 2026Last Modified: 23 Apr 2026
Summary: Malicious code in bmg-web-features (npm)
Details: Source: amazon-inspector (95e385a0f1c1bcc075d39332c519b28aebc80cd8474cbc78baff5ce19661b85f) The package bmg-web-features was found to contain malicious code. Source: ossf-package-analysis (4c1019887de50566ea9613d5f52b7053ef8ce60908337628432831aa4e3dd63d) The OpenSSF Package Analysis project identified 'bmg-web-features' @ 999.99.9 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References:
Affected packages
Package
Name: bmg-web-features
Purl: pkg:npm/bmg-web-features
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
999.99.9
