OSV Malicious Advisory
scanned 3h ago · by OpenSSF/OSVOpenSSF/OSV advisory MAL-2026-6760 confirms this npm version as malicious. The OpenSSF Package Analysis project identified '@adobesign/as-dev-tools' @ 99.9.10 (npm) as malicious.
Advisory
MAL-2026-6760
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @adobesign/as-dev-tools (npm)
Details
The OpenSSF Package Analysis project identified '@adobesign/as-dev-tools' @ 99.9.10 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
Decision reason
OpenSSF Malicious Packages via OSV confirms @adobesign/as-dev-tools@99.9.10 as malicious (MAL-2026-6760): Malicious code in @adobesign/as-dev-tools (npm)
References
Source & flagged code
0 flaggedNo flagged code excerpts are attached to this scan.
Findings
1 High
HighOsv Malicious Advisory