Malicious code in harmony-app-toolkit (npm)
Malware
Published
Aug 15, 2026
to the GitHub Advisory Database
•
Updated Aug 15, 2026
Description
Published to the GitHub Advisory Database
Aug 15, 2026
Reviewed
Aug 15, 2026
Last updated
Aug 15, 2026
Source: ossf-package-analysis (fff7c26e7d15d67157e1b61e4279a0441a9c09fe5c1ef5ad94a8c5ce1b320156)
The OpenSSF Package Analysis project identified 'harmony-app-toolkit' @ 22.0.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
Credit: OpenSSF (source)
References