VDB

GCVE-110-NPM-2026-000202

GCVE-110-NPM-2026-000202
Advisory Published
Vulnetix · Advisory published June 16, 2026
The npm package `hplx-feature-library` (version 1.0.448) was flagged as malicious by automated package analysis (2 evidence detection(s)). Installing it may execute attacker-controlled code via lifecycle scripts or bundled JavaScript. This verdict is produced by static analysis and is subject to human review.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
npmhplx-feature-library* (affected)

References

advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›