UNKNOWNMAL-2026-2297

Malicious code in earthengine-api (npm)

Platform

nodejs

Component

earthengine-api

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (367514ccbb2bca5ad75eda53d2890a583e465233d2b6915acffa09d299405277) The package earthengine-api was found to contain malicious code. ## Source: ossf-package-analysis (a10cd169aad2eb0020abda62fd70a8927f63dfe4ae1891c9256882a03019cf0d) The OpenSSF Package Analysis project identified 'earthengine-api' @ 9.0.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

How to fix

No official patch available. Check for workarounds or monitor for updates.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free
MAL-2026-2297 — Vulnerability Details | NextGuard | NextGuard