MAL-2024-1847

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/business-kpi-manager/MAL-2024-1847.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-1847
Published
2024-06-25T12:30:21Z
Modified
2025-03-03T15:08:00Z
Summary
Malicious code in business-kpi-manager (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (d40c2ea693da70760733dd3ec3fd7dd594c8c49c6e937ec9699b9ec831cc960e)

The OpenSSF Package Analysis project identified 'business-kpi-manager' @ 4.0.4 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "e50c66f5aaba8c1ccfaa2e82e033a82da11c8bccb21c583203e5c2e3c1d563c0",
            "import_time": "2024-06-28T02:42:06.588242233Z",
            "versions": [
                "2.3.0"
            ],
            "id": "RLMA-2024-00444",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T12:30:21Z"
        },
        {
            "sha256": "5d8551cbf195f119da5bf7e861b67f56fa56492ebdb3b2f25435d985e035c49e",
            "import_time": "2024-10-24T00:57:36.462467618Z",
            "id": "RLUA-2024-06256",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T12:36:17Z"
        },
        {
            "sha256": "d40c2ea693da70760733dd3ec3fd7dd594c8c49c6e937ec9699b9ec831cc960e",
            "import_time": "2025-01-22T09:34:36.852550218Z",
            "versions": [
                "4.0.4"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-01-21T16:45:49Z"
        },
        {
            "sha256": "d54e40d9b69a1bb13fcba5c852d84ea8c8ad46d3390ac2976093e9d64b681c0c",
            "import_time": "2025-01-22T21:05:25.730960635Z",
            "versions": [
                "4.0.5"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-01-22T14:35:59Z"
        },
        {
            "sha256": "b18564286d2f85a6383f16bb8fb855da5b7674eb0053cd8ff39b2e26dd2488ff",
            "import_time": "2025-03-03T15:07:23.807344218Z",
            "versions": [
                "4.0.7",
                "4.0.3",
                "4.0.5",
                "4.0.1",
                "4.0.4",
                "4.0.0"
            ],
            "id": "RLUA-2025-00684",
            "source": "reversing-labs",
            "modified_time": "2025-03-03T13:20:43Z"
        }
    ]
}
References
Credits

Affected packages

npm / business-kpi-manager

Package

Name
business-kpi-manager
View open source insights on deps.dev
Purl
pkg:npm/business-kpi-manager

Affected ranges

Affected versions

2.*

2.3.0

4.*

4.0.0
4.0.1
4.0.3
4.0.4
4.0.5
4.0.7