MAL-2024-130

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/noblox.js-proxy-server/MAL-2024-130.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-130
Published
2024-01-16T23:40:53Z
Modified
2024-01-18T03:34:20Z
Summary
Malicious code in noblox.js-proxy-server (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (2b3d7766d2ada5a6d17ae9ae430365649d4034341202ba6fc6a07a0ab6a553fb)

The OpenSSF Package Analysis project identified 'noblox.js-proxy-server' @ 4.15.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "import_time": "2024-01-18T03:33:58.662712809Z",
            "sha256": "2b3d7766d2ada5a6d17ae9ae430365649d4034341202ba6fc6a07a0ab6a553fb",
            "versions": [
                "4.15.1"
            ],
            "modified_time": "2024-01-16T23:40:53Z"
        },
        {
            "source": "ossf-package-analysis",
            "import_time": "2024-01-18T03:33:58.885484713Z",
            "sha256": "e70da72314ee635f02bb74208c6d901deef9488f5e1984ef0b15934b191dbf61",
            "versions": [
                "4.15.4"
            ],
            "modified_time": "2024-01-17T04:17:43Z"
        },
        {
            "source": "ossf-package-analysis",
            "import_time": "2024-01-18T03:33:58.770061774Z",
            "sha256": "e92f511bfbd1c4efd4d29b82282145c7d987a6969f4084ef25b3579e2837fe1c",
            "versions": [
                "4.15.3"
            ],
            "modified_time": "2024-01-17T00:30:23Z"
        }
    ]
}
References
Credits

Affected packages

npm / noblox.js-proxy-server

Package

Name
noblox.js-proxy-server
View open source insights on deps.dev
Purl
pkg:npm/noblox.js-proxy-server

Affected ranges

Affected versions

4.*

4.15.1
4.15.3
4.15.4