MAL-2024-137

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/froxlor/MAL-2024-137.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-137
Published
2024-01-21T21:17:50Z
Modified
2024-01-21T21:17:50Z
Summary
Malicious code in froxlor (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (445e6f97a516e090b04dc5969fbc1472e2c740461dec0b7769bbe76e5d3b6326)

The OpenSSF Package Analysis project identified 'froxlor' @ 19.0.4 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-01-21T21:17:50Z",
            "import_time": "2024-01-21T21:33:49.587307037Z",
            "versions": [
                "19.0.4"
            ],
            "source": "ossf-package-analysis",
            "sha256": "445e6f97a516e090b04dc5969fbc1472e2c740461dec0b7769bbe76e5d3b6326"
        }
    ]
}
References
Credits

Affected packages

npm / froxlor

Package

Affected ranges

Affected versions

19.*

19.0.4