MAL-2023-1342

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webpack-cli.legacy/MAL-2023-1342.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-1342
Aliases
  • SNYK-JS-WEBPACKCLILEGACY-3336028
Published
2023-05-01T23:44:04Z
Modified
2024-06-28T03:14:43.729355Z
Summary
Malicious code in webpack-cli.legacy (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (22737261df7f74819a3f3f968e6516db5e37f6621827d6148b290f7650b9992f)

The OpenSSF Package Analysis project identified 'webpack-cli.legacy' @ 1.0.0 (npm) as malicious.

It is considered malicious because: - The package communicates with a domain associated with malicious activity.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.0.0"
            ],
            "modified_time": "2023-05-01T23:44:04.442404944Z",
            "sha256": "22737261df7f74819a3f3f968e6516db5e37f6621827d6148b290f7650b9992f",
            "source": "ossf-package-analysis",
            "import_time": "2023-08-10T06:15:30.720757513Z"
        },
        {
            "versions": [
                "1.0.0"
            ],
            "modified_time": "2024-06-25T13:21:42Z",
            "sha256": "36a1cb0f22f58b250c2d77254ba2e5c49ff705178b4225a9df44d41640dc2144",
            "id": "RLMA-2024-02718",
            "source": "reversing-labs",
            "import_time": "2024-06-28T02:46:37.689171445Z"
        }
    ]
}
References
Credits

Affected packages

npm / webpack-cli.legacy

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webpack-cli.legacy/MAL-2023-1342.json"