Critical Malware Feed Entry Detected 2026-07-25
Malware feed entry — cross-referenced from OSV. This package is present in our corpus and is listed as malicious in the public OSV malicious-packages database. Our own scanners did not fire independently on it; we still publish it here so the lookup surface stays complete for tools that query the feed. See /advisories for hand-curated analyses.
Advisory · CLR-2026-62787

@cloudplatform-single-spa/[email protected]

Confirmed malicious via cross-reference with OSV. Held in our corpus for lookup / queryable feed.

Detection details

@cloudplatform-single-spa/[email protected] published to npm, cross-referenced from OSV on 2026-07-25 05:37 UTC.

Our detection pipeline did not fire on this package independently. It is listed here because the OSV public malicious-packages database has an entry for @cloudplatform-single-spa/monaas-ui, and we hold the artifact in our corpus — see the OSV reference in the sidebar.

OSV reference: MAL-2026-4951

This is an auto-generated entry in the codelake malware feed. Hand-curated deep case studies live on /advisories.