MAL-2026-3430
Dashboard / Malicious Package / MAL-2026-3430
MAL-2026-3430
Published: 11 May 2026Last Modified: 12 May 2026
Summary: Malicious code in cplace-bmw-emt-mvp (npm)
Details: Source: amazon-inspector (2b6d2d57176a41f11e925988396ad8549efc86508c1cc13a7130871f48c15b33) The package cplace-bmw-emt-mvp was found to contain malicious code. Source: ossf-package-analysis (a5df536f40d00940affdae35145eefe56cf78dc9302c4b2853776a4ae630182b) The OpenSSF Package Analysis project identified 'cplace-bmw-emt-mvp' @ 2.0.4 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References:
Affected packages
Package
Name: cplace-bmw-emt-mvp
Purl: pkg:npm/cplace-bmw-emt-mvp
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
2.0.4
