MAL-2026-6935
Dashboard / Malicious Package / MAL-2026-6935
MAL-2026-6935
Summary: Malicious code in load-nuxt-dev (npm)
Details: Source: amazon-inspector (cf0f879297070c07197ace88cfb411c61d497ad150e39c2c5c91349737f5d83a) The package name resembles the legitimate Nuxt ecosystem tooling (e.g., @nuxt/load-nuxt), and the version 99.0.3 is a common dependency-confusion / version-inflation shape used to force npm to prefer this artifact over an internal package of the same name. No install-time, import-time, or runtime code paths in the scanned files show credential harvesting, remote-code fetch-and-execute, exfiltration, or backdoor behavior. Because no concrete installer-harm mechanism was observed, this cannot be classified as an active attack from the current artifact contents alone, but the name + inflated-version pattern is consistent with a dependency-confusion lure and warrants human review before allowing it into a build. Source: ghsa-malware (ea12ca543df3d9e501a957a114de2ccf0a0f5de9615ae87d087a85e8260491e0) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://github.com/advisories/GHSA-6mpp-f748-7f4q, https://www.npmjs.com/package/load-nuxt-dev/v/99.0.3
Affected packages
Package
Name: load-nuxt-dev
Purl: pkg:npm/load-nuxt-dev
Affected ranges
Type: SEMVER
Events:
