MAL-2023-1185

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gd-company-updates/MAL-2023-1185.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-1185
Published
2023-06-01T12:51:29Z
Modified
2023-08-10T06:17:48Z
Summary
Malicious code in gd-company-updates (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (c1253df2e743d9b41ff76588069c9ee739cc67b4ca244e95405d4b949bcdfb2b)

The OpenSSF Package Analysis project identified 'gd-company-updates' @ 14.999.0 (npm) as malicious.

It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "8.999.0"
            ],
            "modified_time": "2023-06-06T15:09:51.818652557Z",
            "sha256": "4a507a1387ef1a556a0e00ec017153c46b6c91a30797f43248da1a6d91614bb2",
            "source": "ossf-package-analysis",
            "import_time": "2023-08-10T06:17:23.292181906Z"
        },
        {
            "versions": [
                "9.999.0"
            ],
            "modified_time": "2023-06-01T12:51:29.437773272Z",
            "sha256": "50d747c4249d448a464b9e5ad697be00d409a5956f30ee6891f94dd03ea4ff75",
            "source": "ossf-package-analysis",
            "import_time": "2023-08-10T06:17:19.039708989Z"
        },
        {
            "versions": [
                "14.999.0"
            ],
            "modified_time": "2023-06-01T13:56:50.258425849Z",
            "sha256": "c1253df2e743d9b41ff76588069c9ee739cc67b4ca244e95405d4b949bcdfb2b",
            "source": "ossf-package-analysis",
            "import_time": "2023-08-10T06:17:19.281011565Z"
        }
    ]
}
References
Credits

Affected packages

npm / gd-company-updates

Package

Affected ranges

Affected versions

8.*
8.999.0
9.*
9.999.0
14.*
14.999.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gd-company-updates/MAL-2023-1185.json"