@emilgroup/api-documentation
MAL-2026-2035
npmbackdoor3/22/2026
Description
Malicious code in @emilgroup/api-documentation (npm)
Indicators of Compromise
SHA256 Hashes (3)
9576b13d3aaefbc259b6cb9884ca1528d40d49f40b2cc4a91b37e1d33a2143a7
58c245a310d05383d1fdf2e98691e5ea42d0505bdab8e27120537609d6bb4acd
25151e54c9718dfa72de2ed072f606def89e8730a724bd38da926a739ee11a43
Domains (1)
litellm.cloud
Details
Ecosystemnpm
Attack Typebackdoor
Published3/22/2026
Affected Versions
1.19.10
Aliases
GHSA-wq88-f86r-hgrh
Quick Actions