MAL-2024-11912

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/focal-examples/MAL-2024-11912.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-11912
Published
2024-12-18T09:59:04Z
Modified
2024-12-20T00:22:07Z
Summary
Malicious code in focal-examples (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (a810e0097be46a2d0ef76ac3c6aa2088c3467e69485c408f22014bc66dd07530)

The OpenSSF Package Analysis project identified 'focal-examples' @ 9.9.9 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "a810e0097be46a2d0ef76ac3c6aa2088c3467e69485c408f22014bc66dd07530",
            "import_time": "2024-12-18T10:06:04.638955231Z",
            "versions": [
                "9.9.9"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-18T09:59:04Z"
        },
        {
            "sha256": "29b0fb3c0ca96638ee023e4d20c023b93c89699aca06fee01e7d50e371fec522",
            "import_time": "2024-12-20T00:21:37.677697557Z",
            "versions": [
                "9.9.12"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-19T21:30:58Z"
        },
        {
            "sha256": "4a37bf9324ce9ae42876943d3c5d7bf09efa7fc1db409f9d050e13bf97d05e5f",
            "import_time": "2024-12-20T00:21:37.564145945Z",
            "versions": [
                "9.9.10"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-19T21:00:46Z"
        }
    ]
}
References
Credits

Affected packages

npm / focal-examples

Package

Affected ranges

Affected versions

9.*

9.9.9
9.9.10
9.9.12