MAL-2023-1163

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/donuts.node-build/MAL-2023-1163.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-1163
Aliases
  • SNYK-JS-DONUTSNODEBUILD-3336105
Published
2023-04-29T01:25:55Z
Modified
2024-06-28T03:14:34.357631Z
Summary
Malicious code in donuts.node-build (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6b8d6fee5827de9688cc9b83812dc32e54e33531a0bd2fd179dc3e2935564dc7)

The OpenSSF Package Analysis project identified 'donuts.node-build' @ 99.99.104 (npm) as malicious.

It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2023-08-10T06:15:14.219149157Z",
            "source": "ossf-package-analysis",
            "versions": [
                "99.99.104"
            ],
            "modified_time": "2023-04-29T01:25:55.064602162Z",
            "sha256": "6b8d6fee5827de9688cc9b83812dc32e54e33531a0bd2fd179dc3e2935564dc7"
        },
        {
            "id": "RLMA-2024-00761",
            "import_time": "2024-06-28T02:42:44.189166072Z",
            "source": "reversing-labs",
            "versions": [
                "99.99.100",
                "99.99.99",
                "99.99.103",
                "99.99.102",
                "99.99.101",
                "99.99.104"
            ],
            "modified_time": "2024-06-25T12:37:22Z",
            "sha256": "57c72b78d3d0ae13422d294fc842952644fdc2f4f3f021eda149ed06f671673f"
        }
    ]
}
References
Credits

Affected packages

npm / donuts.node-build

Package

Affected ranges

Affected versions

99.*
99.99.99
99.99.100
99.99.101
99.99.102
99.99.103
99.99.104

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/donuts.node-build/MAL-2023-1163.json"