MAL-2024-2348

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/example-arc-server-request-local/MAL-2024-2348.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-2348
Published
2024-06-25T12:42:19Z
Modified
2025-05-19T00:26:49Z
Summary
Malicious code in example-arc-server-request-local (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (f47e48a4969642e3e6ab7d39b5d8f25a7a6d7acf2bbeec054888cfeada839219)

The OpenSSF Package Analysis project identified 'example-arc-server-request-local' @ 100.0.1 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "5dd3b4899189b768f645ff73ba3f98caca313f5aaf3b3f3ab51a2bbe6d55c795",
            "import_time": "2024-06-28T02:43:12.010286192Z",
            "versions": [
                "7.999.1"
            ],
            "id": "RLMA-2024-00990",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T12:42:19Z"
        },
        {
            "sha256": "f2c4d6d813319bc5fc31c8c93d74e5242db82db28acbb2ef4f1ed159986cba8d",
            "import_time": "2024-10-24T00:57:49.096774259Z",
            "id": "RLUA-2024-06540",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T12:51:38Z"
        },
        {
            "sha256": "f47e48a4969642e3e6ab7d39b5d8f25a7a6d7acf2bbeec054888cfeada839219",
            "import_time": "2025-05-19T00:26:17.456979867Z",
            "versions": [
                "100.0.1"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T21:28:42Z"
        },
        {
            "sha256": "f823e9d8679a01573d766f96d92f455f3be1af4dac2463553e7e1c7b0700ba02",
            "import_time": "2025-05-19T00:26:18.07039733Z",
            "versions": [
                "100.0.2"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T22:22:11Z"
        }
    ]
}
References
Credits

Affected packages

npm / example-arc-server-request-local

Package

Name
example-arc-server-request-local
View open source insights on deps.dev
Purl
pkg:npm/example-arc-server-request-local

Affected ranges

Affected versions

7.*

7.999.1

100.*

100.0.1
100.0.2