MAL-2026-10881

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@irys-solutions/odesa-main/MAL-2026-10881.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10881
Aliases
  • GHSA-hmhf-84x5-f526
Published
2026-07-20T10:22:26Z
Modified
2026-09-01T11:30:39Z
Summary
Malicious code in @irys-solutions/odesa-main (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (525ae6b33885c1153dac485b830c8977b433ba4cdd2cc9556415b146ed801569)

No malicious behavior was identified in this package version. No lifecycle scripts performing remote fetches, no credential reads, no exfiltration endpoints, and no suspicious code patterns were observed. With only two files in the package and no concerning content, there is no evidence of installer-side harm.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-05434",
            "import_time": "2026-07-20T13:14:40.335170147Z",
            "modified_time": "2026-07-20T10:22:26Z",
            "sha256": "3f20fc0b546aeb9bdc71496f30839ce40239b21a9e133237b35e3f5f28078cba",
            "source": "reversing-labs",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-013255",
            "import_time": "2026-08-05T06:00:58.849608944Z",
            "modified_time": "2026-08-05T05:56:40Z",
            "sha256": "525ae6b33885c1153dac485b830c8977b433ba4cdd2cc9556415b146ed801569",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "RLUA-2026-05878",
            "import_time": "2026-09-01T11:17:42.212823552Z",
            "modified_time": "2026-08-24T16:24:59Z",
            "sha256": "c355ce2b7e587ca55ec965d0a97bbee29cb7f51504d715455ee6b4e48dfd99be",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / @irys-solutions/odesa-main

Package

Name
@irys-solutions/odesa-main
View open source insights on deps.dev
Purl
pkg:npm/%40irys-solutions/odesa-main

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "odesa-main-1.0.0.tgz",
            "hashes": {
                "sha1": "e529283b37ccc6b18cfb37cea875cd8e9f395252",
                "sha512_sri": "sha512-2YMWvazprxDZm9llz86fJpnAnff/ZWHj+g58Igdpm+yyvvldEoXKLrVeODnA8r1izdD+uw1KpK/KJXXE7hehPg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@irys-solutions/odesa-main/MAL-2026-10881.json"