Malicious npm package executing base64-decoded shell command to download and run stage-2 payload from C2 server (89.36.224.5) targeting macOS
{ "malicious-packages-origins": null }
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@velora-dex/sdk/MAL-2026-2510.json"