MAL-2026-4161

    Dashboard / Malicious Package / MAL-2026-4161

    MAL-2026-4161

    Published: 19 May 2026Last Modified: 19 May 2026

    Summary: Malicious code in @cap-js/openapi (npm)

    Details: Source: amazon-inspector (243c059793e8b277fc77959046b7b064cb740d568fa53e4d30b9075660d9dab5) The package @cap-js/openapi was found to contain malicious code. Source: google-open-source-security (847ef6b381d410bf176f7414a6f0fbbcf46a5f39b6d9011e126b279bd2d781df) This package was compromised as part of the ongoing "Mini Shai-Hulud is back" worm by the TeamPCP threat actor. The package will steal credentials and then propogate it to every package it has access to. The package also attempts to remain persistent.

    Affected packages

    Package

    Name: @cap-js/openapi

    Purl: pkg:npm/%40cap-js%2Fopenapi

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.4.1
    MAL-2026-4161 | CVE-DB