npm
Malicious @mc-xp/mc-monolith-js-src-package @99.9.1
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 3:29 AM UTC
OSV ID
MAL-2026-4171
Ecosystem
npm
Summary
The OpenSSF Package Analysis project identified '@mc-xp/mc-monolith-js-src-package' @ 99.9.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Source: ossf-package-analysis (13fafa7ca25af537c9383868398521cf50a086c1055e9451e4a2208de0083923)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.