Malicious post-install script combined with low project popularity indicates potential malware. Arbitrary code execution is a major concern.
-= Per source details. Do not edit below this line.=-
The package @the-coca-cola-company/ngps-global-common-utils was found to contain malicious code.
{
"malicious-packages-origins": [
{
"import_time": "2026-04-07T14:39:17.98122271Z",
"sha256": "3ebe31c5bb51c354ed83627a02c11ca4c8541e042623b1b987255941ffafdaff",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"source": "amazon-inspector",
"modified_time": "2026-04-07T14:24:50Z"
},
{
"id": "RLMA-2026-01868",
"sha256": "c8f9e8cd86ecaa7f2080db546f0064ff49df1a741be0cfa86f17778ae97f2fe2",
"import_time": "2026-04-16T15:38:50.59739279Z",
"source": "reversing-labs",
"modified_time": "2026-04-16T09:39:20Z",
"versions": [
"1.0.0",
"9.9.0",
"9.9.9"
]
}
]
}