MAL-2024-1039

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/is24-desktop/MAL-2024-1039.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-1039
Published
2024-02-27T17:54:26Z
Modified
2024-03-04T05:49:30Z
Summary
Malicious code in is24-desktop (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (1f924b1c86b042837547c3f1942013a3f4b791af2a22914a1694ba2a0b90b61a)

The OpenSSF Package Analysis project identified 'is24-desktop' @ 18.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "6d3155c5fdeb62a989de80674505c333ab33f5cc211f7c8771f7627ff663d771",
            "import_time": "2024-02-27T18:05:50.23891484Z",
            "versions": [
                "17.0.0"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-02-27T17:54:26Z"
        },
        {
            "sha256": "1f924b1c86b042837547c3f1942013a3f4b791af2a22914a1694ba2a0b90b61a",
            "import_time": "2024-02-27T19:04:58.399213511Z",
            "versions": [
                "18.0.0"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-02-27T18:35:54Z"
        },
        {
            "sha256": "8ada6ca8c5150cc9c2f964770eb16632e7e3fd36d4d0489b10ef5b642f3a2f63",
            "import_time": "2024-03-04T05:49:09.826312175Z",
            "versions": [
                "19.0.0"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-02-27T18:45:51Z"
        },
        {
            "sha256": "bfc403b37beae871d2960a4fe4c3b3108b9d8dbb98f618f7de1bd4c1650d4f6a",
            "import_time": "2024-03-04T05:49:09.91372691Z",
            "versions": [
                "20.0.0"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-02-27T19:10:41Z"
        }
    ]
}
References
Credits

Affected packages

npm / is24-desktop

Package

Affected ranges

Affected versions

17.*

17.0.0

18.*

18.0.0

19.*

19.0.0

20.*

20.0.0