MAL-2026-2954

    Dashboard / Malicious Package / MAL-2026-2954

    MAL-2026-2954

    Published: 20 Apr 2026Last Modified: 23 Apr 2026

    Summary: Malicious code in bmg-web-features (npm)

    Details: Source: amazon-inspector (95e385a0f1c1bcc075d39332c519b28aebc80cd8474cbc78baff5ce19661b85f) The package bmg-web-features was found to contain malicious code. Source: ossf-package-analysis (4c1019887de50566ea9613d5f52b7053ef8ce60908337628432831aa4e3dd63d) The OpenSSF Package Analysis project identified 'bmg-web-features' @ 999.99.9 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    References:

    Affected packages

    Package

    Name: bmg-web-features

    Purl: pkg:npm/bmg-web-features

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    999.99.9
    MAL-2026-2954 | CVE-DB