MAL-2024-9263

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@copilot-web-widgets/ai-writer/MAL-2024-9263.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-9263
Published
2024-10-10T21:58:53Z
Modified
2024-10-11T04:06:44Z
Summary
Malicious code in @copilot-web-widgets/ai-writer (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (370d6b958dcc6a556f2ee4be3946c6a1a995bb05d4217f408f2302dd397689a2)

The OpenSSF Package Analysis project identified '@copilot-web-widgets/ai-writer' @ 1.13.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.13.1"
            ],
            "sha256": "370d6b958dcc6a556f2ee4be3946c6a1a995bb05d4217f408f2302dd397689a2",
            "modified_time": "2024-10-10T22:10:42Z",
            "source": "ossf-package-analysis",
            "import_time": "2024-10-11T04:06:21.264217451Z"
        },
        {
            "versions": [
                "1.12.0"
            ],
            "sha256": "817441063451fd9c550d63008824f12e22b699d6bb16647d8f59cb532dc355cb",
            "modified_time": "2024-10-10T21:58:53Z",
            "source": "ossf-package-analysis",
            "import_time": "2024-10-11T04:06:21.120950625Z"
        },
        {
            "versions": [
                "1.14.0"
            ],
            "sha256": "84e6ed4b921dc4d50dafc276ec384248c5f4b0cc7bf5bc7eab122eebc282792a",
            "modified_time": "2024-10-10T22:20:41Z",
            "source": "ossf-package-analysis",
            "import_time": "2024-10-11T04:06:21.392651297Z"
        },
        {
            "versions": [
                "1.13.0"
            ],
            "sha256": "fa15f340a346d1ec15438d8b57b8791bb4a74071f6827a4581f3fd4cb1b5254f",
            "modified_time": "2024-10-10T22:00:47Z",
            "source": "ossf-package-analysis",
            "import_time": "2024-10-11T04:06:21.186231794Z"
        }
    ]
}
References
Credits

Affected packages

npm / @copilot-web-widgets/ai-writer

Package

Name
@copilot-web-widgets/ai-writer
View open source insights on deps.dev
Purl
pkg:npm/%40copilot-web-widgets/ai-writer

Affected ranges

Affected versions

1.*
1.12.0
1.13.0
1.13.1
1.14.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@copilot-web-widgets/ai-writer/MAL-2024-9263.json"