CWE-50635 advisories

Embedded Malicious Code

What it is

The package itself contains malicious code (a supply-chain compromise or malicious publish).

How to fix it

Remove the package immediately, rotate any exposed secrets, and pin to a known-good version.

How to avoid it

Pin and verify dependencies, watch for typosquats, and review new maintainers/publishes.

Known Embedded Malicious Code vulnerabilities

Stateward flags Embedded Malicious Code in your own code and dependencies on every pull request.

Scan my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.