MAL-2023-1164

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dox_assets/MAL-2023-1164.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-1164
Published
2023-07-26T13:31:39Z
Modified
2024-09-27T04:06:48Z
Summary
Malicious code in dox_assets (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6c57cd0d4a4f51e1d3075405f2b7f898a8a54edb38311287c357f835719f6cc8)

The OpenSSF Package Analysis project identified 'dox_assets' @ 100.5.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "7.5.0"
            ],
            "modified_time": "2023-07-26T13:31:39.582160533Z",
            "source": "ossf-package-analysis",
            "sha256": "28658e478f18753571d3fc91e3963dae24e8aa7231be5fe0ea04674fd2d4b10b",
            "import_time": "2023-08-10T06:16:47.365816009Z"
        },
        {
            "versions": [
                "100.5.0"
            ],
            "modified_time": "2024-09-27T04:03:28Z",
            "source": "ossf-package-analysis",
            "sha256": "6c57cd0d4a4f51e1d3075405f2b7f898a8a54edb38311287c357f835719f6cc8",
            "import_time": "2024-09-27T04:06:24.076954106Z"
        }
    ]
}
References
Credits

Affected packages

npm / dox_assets

Package

Affected ranges

Affected versions

7.*

7.5.0

100.*

100.5.0