MAL-2024-10227

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@woody-mrs-potato/utils-banking/MAL-2024-10227.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-10227
Published
2024-10-24T12:11:04Z
Modified
2024-12-12T16:40:44Z
Summary
Malicious code in @woody-mrs-potato/utils-banking (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (1466f5d4f097f853c6a448bec817a35b2d4173df50bee1404ba4b46433387349)

The OpenSSF Package Analysis project identified '@woody-mrs-potato/utils-banking' @ 1.0.5 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.0.2"
            ],
            "modified_time": "2024-10-24T12:11:04Z",
            "source": "ossf-package-analysis",
            "sha256": "df225116ff9ceb8a292dceb5da25019ca7d3d3ee9786867d47654b33cae303b4",
            "import_time": "2024-10-24T12:46:13.019071152Z"
        },
        {
            "versions": [
                "1.0.5"
            ],
            "modified_time": "2024-11-05T15:08:16Z",
            "source": "ossf-package-analysis",
            "sha256": "1466f5d4f097f853c6a448bec817a35b2d4173df50bee1404ba4b46433387349",
            "import_time": "2024-11-05T15:35:14.124279967Z"
        },
        {
            "versions": [
                "1.0.6"
            ],
            "modified_time": "2024-11-05T15:25:53Z",
            "source": "ossf-package-analysis",
            "sha256": "6f5cbbeee0acb7981a38702efe5788cefc4678e64277b5b7da50336e56c2f909",
            "import_time": "2024-11-05T15:35:14.191367808Z"
        },
        {
            "versions": [
                "1.0.8"
            ],
            "modified_time": "2024-12-12T16:31:21Z",
            "source": "ossf-package-analysis",
            "sha256": "3908faf9be2940aa913bb07064d097afd6140be6fc6c2be476a90ca254c2ddd5",
            "import_time": "2024-12-12T16:40:11.981647255Z"
        }
    ]
}
References
Credits

Affected packages

npm / @woody-mrs-potato/utils-banking

Package

Name
@woody-mrs-potato/utils-banking
View open source insights on deps.dev
Purl
pkg:npm/%40woody-mrs-potato/utils-banking

Affected ranges

Affected versions

1.*

1.0.2
1.0.5
1.0.6
1.0.8