malware
npm
@needl-ai/common
discovered 2026-04-10@needl-ai/common is identified in the SafeDep analysis "Malicious npm Dependency Confusion Campaign Targets Genoma UI and Others". A dependency confusion campaign by npm user victim59 targets at least three organizations through scoped packages @genoma-ui/components, @needl-ai/common, and rrweb-v1. The packages use install hooks to beacon system reconnaissance data to a DigitalOcean C2 server.
Threat types
c2_agent dependency_confusion
Malicious versions
- 999.9.9