MAL-2024-7726

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/noblox-core-ts/MAL-2024-7726.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-7726
Published
2024-07-11T07:08:33Z
Modified
2024-07-11T07:08:33Z
Summary
Malicious code in noblox-core-ts (npm)
Details

This package is considered malicious because it contains a heavily obfuscated postinstall.js script with multiple stages of payload execution, resulting in the delivery of QuasarRAT. This allows command and control by a malicious actor.

Database specific
{
    "malicious-packages-origins": null
}
References
Credits

Affected packages

npm / noblox-core-ts

Package

Affected ranges

Affected versions

4.*

4.6.6
4.6.7