MAL-2024-3974

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/y-dot/MAL-2024-3974.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-3974
Aliases
  • SNYK-JS-YDOT-3336130
Published
2024-06-25T13:22:34Z
Modified
2024-10-24T01:01:57Z
Summary
Malicious code in y-dot (npm)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "cc53a76f89cbd50856f4df1f0cd826c3edcbc7dbfef5f7e6a4ded0875720d72a",
            "import_time": "2024-06-28T02:46:41.819134953Z",
            "versions": [
                "1.16.8",
                "1.8.16",
                "1.8.9",
                "2.7.3",
                "1.16.9",
                "1.8.8",
                "1.8.17"
            ],
            "id": "RLMA-2024-02751",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T13:22:34Z"
        },
        {
            "sha256": "6c79549a6db0ba8721d0986d30f7913d33137d9ebb69ccb704e875babdbb2143",
            "import_time": "2024-10-24T00:58:34.326853839Z",
            "id": "RLUA-2024-07605",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T13:46:35Z"
        }
    ]
}
References
Credits

Affected packages

npm / y-dot

Package

Affected ranges

Affected versions

1.*

1.8.8
1.8.9
1.8.16
1.8.17
1.16.8
1.16.9

2.*

2.7.3