MAL-2026-3331
Dashboard / Malicious Package / MAL-2026-3331
MAL-2026-3331
Published: 4 May 2026Last Modified: 12 May 2026
Summary: Malicious code in lazyhtml-scripts (npm)
Details: Source: amazon-inspector (45abfd9582509b7e6ded4a7ce678a25aef82365186bba18330d6f76f1cf3c5ea) The package lazyhtml-scripts was found to contain malicious code. Source: ossf-package-analysis (71844816af603d74c0b28463789c32032f49ba227282ce2b9a735ecc9438bace) The OpenSSF Package Analysis project identified 'lazyhtml-scripts' @ 99.9.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References:
Affected packages
Package
Name: lazyhtml-scripts
Purl: pkg:npm/lazyhtml-scripts
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
99.9.1
