MAL-2024-7746

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/inline-icons/MAL-2024-7746.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-7746
Published
2024-07-15T19:41:23Z
Modified
2024-10-24T01:01:56Z
Summary
Malicious code in inline-icons (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (f9b4dc3b900cda7b3ddba48442ae448f1af310a11854f024134f391baafb62d8)

The OpenSSF Package Analysis project identified 'inline-icons' @ 70.69.69 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "import_time": "2024-07-15T20:05:14.721874546Z",
            "sha256": "f9b4dc3b900cda7b3ddba48442ae448f1af310a11854f024134f391baafb62d8",
            "versions": [
                "70.69.69"
            ],
            "modified_time": "2024-07-15T19:41:23Z"
        },
        {
            "source": "ossf-package-analysis",
            "import_time": "2024-07-23T14:04:51.866546514Z",
            "sha256": "73337237768310ac85c3743769a2fd04c56b5a75919cdbec7151b629174ddd2b",
            "versions": [
                "71.69.69"
            ],
            "modified_time": "2024-07-23T13:38:58Z"
        },
        {
            "id": "RLMA-2024-06738",
            "source": "reversing-labs",
            "import_time": "2024-10-24T00:56:27.652232955Z",
            "sha256": "de9a3ffb93222a658ea5a56b537851e803537179197abd6bb237bca0064e0c7d",
            "versions": [
                "69.69.70",
                "71.69.69",
                "72.69.69"
            ],
            "modified_time": "2024-10-16T12:58:24Z"
        }
    ]
}
References
Credits

Affected packages

npm / inline-icons

Package

Affected ranges

Affected versions

69.*

69.69.70

70.*

70.69.69

71.*

71.69.69

72.*

72.69.69