MAL-2024-11417

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/perfetto-dev/MAL-2024-11417.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-11417
Published
2024-12-09T03:36:13Z
Modified
2025-09-15T00:19:21Z
Summary
Malicious code in perfetto-dev (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (0e720d5c11d5548ad2e3506f0cf7e3f12a64954e0e3affc7acf12689f8d163d6)

The OpenSSF Package Analysis project identified 'perfetto-dev' @ 9.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2024-12-09T14:38:30.311875054Z",
            "source": "reversing-labs",
            "modified_time": "2024-12-09T03:36:13Z",
            "sha256": "910223c3b6d01505bc7af7e8d4a6096e5b877503cc0063f4421cc663693baf2b",
            "versions": [
                "9.9.9"
            ],
            "id": "RLMA-2024-10733"
        },
        {
            "import_time": "2025-08-14T21:05:49.08813846Z",
            "source": "ossf-package-analysis",
            "modified_time": "2025-08-14T20:40:01Z",
            "sha256": "0e720d5c11d5548ad2e3506f0cf7e3f12a64954e0e3affc7acf12689f8d163d6",
            "versions": [
                "9.0.0"
            ]
        },
        {
            "import_time": "2025-08-29T06:42:49.277972708Z",
            "source": "reversing-labs",
            "modified_time": "2025-08-28T07:36:01Z",
            "sha256": "ff13f0ec4776215638cdcbf726d234b83a04bfacb0801f16974df0f0b5a4f0b1",
            "versions": [
                "9.0.0"
            ],
            "id": "RLUA-2025-04628"
        },
        {
            "import_time": "2025-09-13T08:06:24.416723582Z",
            "source": "ossf-package-analysis",
            "modified_time": "2025-09-13T07:56:42Z",
            "sha256": "515f8e70ce820bdbc3a53c5ea84bb85162a379895077a9105f122ef1f0660062",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / perfetto-dev

Package

Affected ranges

Affected versions

1.*

1.0.0

9.*

9.0.0
9.9.9