@emilgroup/docxtemplater-util
MAL-2026-2047
npmbackdoor3/22/2026
Description
Malicious code in @emilgroup/docxtemplater-util (npm)
Indicators of Compromise
SHA256 Hashes (3)
97b77709b03a85bbe22cc4d8a6697312d9a4ab21aab62859dbe38f87d4350dce
1d196d74e7824e876dfcb2ce1d7a1930ef7009f348a1678012c7813f4786080d
889e118088c03c39370b915cb1eff75e1a95ea99eab54b7ca2afe13e6993c086
Domains (1)
litellm.cloud
Details
Ecosystemnpm
Attack Typebackdoor
Published3/22/2026
Aliases
GHSA-f9m8-w27f-mxr3
Quick Actions