MAL-2023-1131

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chain00x_rce1/MAL-2023-1131.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-1131
Published
2023-06-16T17:36:11Z
Modified
2023-08-10T06:17:47Z
Summary
Malicious code in chain00x_rce1 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (2d528fd659506ce3a370f146632641af04a4a41e0c1b4d0e148e48a2b57e8b40)

The OpenSSF Package Analysis project identified 'chain00x_rce1' @ 1.0.1 (npm) as malicious.

It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.0.1"
            ],
            "modified_time": "2023-06-16T17:45:54.473425116Z",
            "source": "ossf-package-analysis",
            "sha256": "2d528fd659506ce3a370f146632641af04a4a41e0c1b4d0e148e48a2b57e8b40",
            "import_time": "2023-08-10T06:17:28.181645399Z"
        },
        {
            "versions": [
                "1.0.2"
            ],
            "modified_time": "2023-06-16T17:46:24.085157101Z",
            "source": "ossf-package-analysis",
            "sha256": "3f0e7e20d1acac8bed85fa52087f79dc00ed64b765fd8274c35ee46b517cfcc6",
            "import_time": "2023-08-10T06:17:28.430829364Z"
        },
        {
            "versions": [
                "1.0.0"
            ],
            "modified_time": "2023-06-16T17:36:11.662882621Z",
            "source": "ossf-package-analysis",
            "sha256": "4eb273e5620ecdf10234201e10e7914611b4014b50e90adbfcdcb7b6ddaf1ef1",
            "import_time": "2023-08-10T06:17:27.924798229Z"
        },
        {
            "versions": [
                "1.0.4"
            ],
            "modified_time": "2023-06-16T17:56:31.155381848Z",
            "source": "ossf-package-analysis",
            "sha256": "6bb9b1d65197c76b7cad2c9c506201e365e26715f123c09bb8d4da4fd8555ae7",
            "import_time": "2023-08-10T06:17:28.7037895Z"
        },
        {
            "versions": [
                "1.0.5"
            ],
            "modified_time": "2023-06-16T18:01:38.219019235Z",
            "source": "ossf-package-analysis",
            "sha256": "96e52b3c8ebfb43052b83033e318df8773cfe73301b0619d6c591bcf0c31733e",
            "import_time": "2023-08-10T06:17:28.987125061Z"
        }
    ]
}
References
Credits

Affected packages

npm / chain00x_rce1

Package

Affected ranges

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.4
1.0.5