MAL-2024-11765

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wf-ceo/react-test-helpers/MAL-2024-11765.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-11765
Published
2024-12-09T23:47:38Z
Modified
2024-12-11T00:50:10Z
Summary
Malicious code in @wf-ceo/react-test-helpers (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (1adea7c44d554247e0db4c0cbcde6166a86b5c7f01033ff049e86e69c818475c)

The OpenSSF Package Analysis project identified '@wf-ceo/react-test-helpers' @ 67.6.7 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-12-10T09:09:23Z",
            "import_time": "2024-12-11T00:49:36.407365581Z",
            "versions": [
                "67.6.7"
            ],
            "source": "ossf-package-analysis",
            "sha256": "1adea7c44d554247e0db4c0cbcde6166a86b5c7f01033ff049e86e69c818475c"
        },
        {
            "modified_time": "2024-12-10T09:45:46Z",
            "import_time": "2024-12-11T00:49:36.629007377Z",
            "versions": [
                "1.1.1"
            ],
            "source": "ossf-package-analysis",
            "sha256": "c7d43e832d3fc7e94e186446b2053aae8d49dd146354de0124c2c844caaba9a8"
        },
        {
            "modified_time": "2024-12-09T23:47:38Z",
            "import_time": "2024-12-11T00:49:36.275292946Z",
            "versions": [
                "67.6.6"
            ],
            "source": "ossf-package-analysis",
            "sha256": "d89002100b20ccc12116694e9e5ddd91a38cc0ed6c5662959ed241e118cb37b8"
        }
    ]
}
References
Credits

Affected packages

npm / @wf-ceo/react-test-helpers

Package

Name
@wf-ceo/react-test-helpers
View open source insights on deps.dev
Purl
pkg:npm/%40wf-ceo/react-test-helpers

Affected ranges

Affected versions

1.*

1.1.1

67.*

67.6.6
67.6.7