MAL-2023-1453

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/marvelmaniac-reddit-rce/MAL-2023-1453.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-1453
Published
2023-08-14T08:40:40Z
Modified
2023-08-14T11:10:12Z
Summary
Malicious code in marvelmaniac-reddit-rce (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (4e0c11328bba9ebf6da62d82fc149892918b5830eef9816b5f887c46f1108fa0)

The OpenSSF Package Analysis project identified 'marvelmaniac-reddit-rce' @ 10.0.3 (npm) as malicious.

It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.1.1"
            ],
            "modified_time": "2023-08-14T08:40:40.515973651Z",
            "source": "ossf-package-analysis",
            "sha256": "10dbf649c9f977defdb670b0f617759be6d81a7c8b152ed0c12706a6c81e564d",
            "import_time": "2023-08-14T09:05:42.305023488Z"
        },
        {
            "versions": [
                "9.9.9"
            ],
            "modified_time": "2023-08-14T09:15:00.557234643Z",
            "source": "ossf-package-analysis",
            "sha256": "6592dfe8d7b6a5c8e1ffcd328000b371dce64ba230547f8f34478c527285f2c7",
            "import_time": "2023-08-14T09:34:41.926333526Z"
        },
        {
            "versions": [
                "10.0.3"
            ],
            "modified_time": "2023-08-14T10:45:38.70369614Z",
            "source": "ossf-package-analysis",
            "sha256": "4e0c11328bba9ebf6da62d82fc149892918b5830eef9816b5f887c46f1108fa0",
            "import_time": "2023-08-14T11:04:53.168218695Z"
        }
    ]
}
References
Credits

Affected packages

npm / marvelmaniac-reddit-rce

Package

Name
marvelmaniac-reddit-rce
View open source insights on deps.dev
Purl
pkg:npm/marvelmaniac-reddit-rce

Affected ranges

Affected versions

1.*

1.1.1

9.*

9.9.9

10.*

10.0.3