MAL-2024-1168

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/qlik-sense-poc/MAL-2024-1168.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-1168
Published
2024-04-02T19:06:34Z
Modified
2024-04-02T22:34:16Z
Summary
Malicious code in qlik-sense-poc (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (e3ca1728f46e0ecfd22305ab1dd8de7134e1d067e7c76f5d9e4871424fbf9148)

The OpenSSF Package Analysis project identified 'qlik-sense-poc' @ 5.5.991 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "5.5.99"
            ],
            "modified_time": "2024-04-02T19:06:34Z",
            "source": "ossf-package-analysis",
            "sha256": "0ab92f1077a0cc13ce5b1eb263a6e89d74640e589c1e383d05a68a2560be2160",
            "import_time": "2024-04-02T19:33:58.265032007Z"
        },
        {
            "versions": [
                "5.5.991"
            ],
            "modified_time": "2024-04-02T20:50:48Z",
            "source": "ossf-package-analysis",
            "sha256": "e3ca1728f46e0ecfd22305ab1dd8de7134e1d067e7c76f5d9e4871424fbf9148",
            "import_time": "2024-04-02T21:04:47.583060269Z"
        },
        {
            "versions": [
                "5.5.992"
            ],
            "modified_time": "2024-04-02T22:20:07Z",
            "source": "ossf-package-analysis",
            "sha256": "235f7bd79a1fe67306e75e5b0a0af807e25f3c31fbb11a88d09403162db67f1c",
            "import_time": "2024-04-02T22:33:56.536758096Z"
        }
    ]
}
References
Credits

Affected packages

npm / qlik-sense-poc

Package

Affected ranges

Affected versions

5.*

5.5.99
5.5.991
5.5.992