MAL-2024-43

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/noblox.js-servers/MAL-2024-43.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-43
Published
2024-01-07T01:50:07Z
Modified
2024-01-07T03:34:12Z
Summary
Malicious code in noblox.js-servers (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (be4b415c87e9f3008a2d199fcc914e49a3a8a047e4bdfcaa493a9364d54accf7)

The OpenSSF Package Analysis project identified 'noblox.js-servers' @ 4.15.8 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "modified_time": "2024-01-07T01:51:04Z",
            "import_time": "2024-01-07T02:17:14.882007503Z",
            "versions": [
                "4.15.8"
            ],
            "sha256": "be4b415c87e9f3008a2d199fcc914e49a3a8a047e4bdfcaa493a9364d54accf7"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2024-01-07T01:50:07Z",
            "import_time": "2024-01-07T02:17:14.769189579Z",
            "versions": [
                "4.15.7"
            ],
            "sha256": "f48d7814e2fc62e16b780d75b185f49b846fc9a6a063fac8eda4cd228e1ba407"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2024-01-07T02:51:19Z",
            "import_time": "2024-01-07T03:05:13.397304203Z",
            "versions": [
                "4.16.2"
            ],
            "sha256": "555fe97514c17ef3201d2710c8fc66643b03cd64601c3286e11eaa017a0cc2d5"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2024-01-07T03:10:53Z",
            "import_time": "2024-01-07T03:33:55.621973024Z",
            "versions": [
                "4.16.3"
            ],
            "sha256": "3018ef5932a0c25bd2ec9aa051e3bb913b4cd4c8ec69d737759c50fa19e655da"
        }
    ]
}
References
Credits

Affected packages

npm / noblox.js-servers

Package

Affected ranges

Affected versions

4.*

4.15.7
4.15.8
4.16.2
4.16.3