MAL-2024-30

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axelhowe/MAL-2024-30.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-30
Published
2024-01-04T07:00:13Z
Modified
2024-01-04T07:00:13Z
Summary
Malicious code in axelhowe (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (9a6b8a2beae8966a71fb077b1adaef5f5a2fdd01e92c2bdfed182d06a8745435)

The OpenSSF Package Analysis project identified 'axelhowe' @ 0.0.0-5VtLmtixx6V5PkcW (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "9a6b8a2beae8966a71fb077b1adaef5f5a2fdd01e92c2bdfed182d06a8745435",
            "modified_time": "2024-01-04T07:00:13Z",
            "import_time": "2024-01-04T07:05:06.795179603Z",
            "source": "ossf-package-analysis",
            "versions": [
                "0.0.0-5VtLmtixx6V5PkcW"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / axelhowe

Package

Affected ranges

Affected versions

0.*

0.0.0-5VtLmtixx6V5PkcW