Vulnerabilities/

Malware in @opensearch-project/opensearch

Severity:
High

Description

The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project’s CI infrastructure to embed malicious packages into four release versions of @opensearch-project/opensearch.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@opensearch-project/opensearch
Anything's wrong? Let us know Last updated on May 19, 2026