PkgRadar

Malware advisory

MAL-2024-1006

Malicious code in @ebay/ui-core-react (npm)

13 affected releases in the PkgRadar corpus · published 2024-02-15 · upstream advisory

Affected packages

Every release listed here is malicious per this advisory and is blocked at the CI gate. The Static scancolumn is PkgRadar’s independent static-analysis result for that release — some malicious releases score low on static signals alone, which is why we also mirror the advisory as authoritative.

PackageEcosystemVersionStatic scanScanned (UTC)
@ebay/ui-core-reactnpm9.10.0Low risk2026-07-14
@ebay/ui-core-reactnpm9.9.0Low risk2026-07-14
@ebay/ui-core-reactnpm9.8.2Low risk2026-07-14
@ebay/ui-core-reactnpm9.8.1Low risk2026-07-14
@ebay/ui-core-reactnpm9.6.5Low risk2026-07-14
@ebay/ui-core-reactnpm9.8.0Low risk2026-07-14
@ebay/ui-core-reactnpm9.7.0Low risk2026-07-14
@ebay/ui-core-reactnpm9.6.3Low risk2026-07-14
@ebay/ui-core-reactnpm9.3.0Low risk2026-07-14
@ebay/ui-core-reactnpm9.6.6Low risk2026-07-14
@ebay/ui-core-reactnpm9.6.4Low risk2026-07-14
@ebay/ui-core-reactnpm9.4.0Low risk2026-07-14
@ebay/ui-core-reactnpm9.3.1Low risk2026-07-14

PkgRadar blocks these releases at the CI gate before they reach your build. Start free or see all advisories.

Malicious code in @ebay/ui-core-react (npm) — malware advisory MAL-2024-1006 | PkgRadar