MAL-2024-2

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cartus-core/cartus-common-ui/MAL-2024-2.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-2
Published
2024-01-01T12:33:38Z
Modified
2024-01-01T22:33:56Z
Summary
Malicious code in @cartus-core/cartus-common-ui (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (00ecedfab923e26d9afa1c15157b18d4f9662f062ffec7f4ce93ece0426eeeda)

The OpenSSF Package Analysis project identified '@cartus-core/cartus-common-ui' @ 11230000951.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "200000001.0.0"
            ],
            "modified_time": "2024-01-01T12:33:38Z",
            "sha256": "e1cb0428ec77f27833f104360225710f2669706df0702c7779e3cf3f1b4946d6",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T12:40:45.688977557Z"
        },
        {
            "versions": [
                "200000051.0.0"
            ],
            "modified_time": "2024-01-01T12:47:56Z",
            "sha256": "664b0901400ee7c7d3f40110ce2925f5b513ac75de888ee2d86f4c25a4354216",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T13:05:18.584352665Z"
        },
        {
            "versions": [
                "230000951.0.0"
            ],
            "modified_time": "2024-01-01T19:03:34Z",
            "sha256": "642a26bc2539e5716fd7cd404408efe760e83b09c9ccb1b487c3e2831395edd8",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T19:04:49.956377949Z"
        },
        {
            "versions": [
                "230000051.0.0"
            ],
            "modified_time": "2024-01-01T18:37:18Z",
            "sha256": "fb07fdb9bd3d95181ea1d455158c7e136d17dfaa4ca9164facebf0172a704760",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T19:04:49.749197782Z"
        },
        {
            "versions": [
                "11230000951.0.1"
            ],
            "modified_time": "2024-01-01T19:30:03Z",
            "sha256": "00ecedfab923e26d9afa1c15157b18d4f9662f062ffec7f4ce93ece0426eeeda",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T19:33:40.37183478Z"
        },
        {
            "versions": [
                "11230000951.0.0"
            ],
            "modified_time": "2024-01-01T19:31:58Z",
            "sha256": "d52531303a037510d34ec70b702e6614a8b11a8804f488315ef46c3e3b2a7ffa",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T19:33:40.426289368Z"
        },
        {
            "versions": [
                "11230000951.0.7"
            ],
            "modified_time": "2024-01-01T21:38:56Z",
            "sha256": "80539c4f71f44880d4451abb7d4680b70b2026ba5a5c8a2edcc4386c192a82a9",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T22:04:55.13449038Z"
        },
        {
            "versions": [
                "11230000951.0.4"
            ],
            "modified_time": "2024-01-01T20:47:17Z",
            "sha256": "08f603e0b5cc16b8586f4f231aa2b8194beefed9e3ad5e7a2240ac0b0d823bd9",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T22:33:40.10017918Z"
        },
        {
            "versions": [
                "11230000951.0.3"
            ],
            "modified_time": "2024-01-01T20:40:31Z",
            "sha256": "2c044429d884da1d1ce4092e67062df0e85ebfc03b014b312907cbac4890635e",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T22:33:39.95912093Z"
        },
        {
            "versions": [
                "11230000951.0.5"
            ],
            "modified_time": "2024-01-01T21:15:45Z",
            "sha256": "a4730652997024ebd6ac5facfa4fe30f55d7fd427f749ca4fccfc559b57f164f",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T22:33:40.333767826Z"
        },
        {
            "versions": [
                "11230000951.0.2"
            ],
            "modified_time": "2024-01-01T20:00:39Z",
            "sha256": "ef137d971261f9aade7b489f2ca1c5b44140e773fc7ab21c747c2061e15eb253",
            "source": "ossf-package-analysis",
            "import_time": "2024-01-01T22:33:39.772167131Z"
        }
    ]
}
References
Credits

Affected packages

npm / @cartus-core/cartus-common-ui

Package

Name
@cartus-core/cartus-common-ui
View open source insights on deps.dev
Purl
pkg:npm/%40cartus-core/cartus-common-ui

Affected ranges

Affected versions

200000001.*
200000001.0.0
200000051.*
200000051.0.0
230000051.*
230000051.0.0
230000951.*
230000951.0.0
11230000951.*
11230000951.0.0
11230000951.0.1
11230000951.0.2
11230000951.0.3
11230000951.0.4
11230000951.0.5
11230000951.0.7

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cartus-core/cartus-common-ui/MAL-2024-2.json"