-= Per source details. Do not edit below this line.=-
No malicious behavior was identified in this package version. No lifecycle scripts performing remote fetches, no credential reads, no exfiltration endpoints, and no suspicious code patterns were observed. With only two files in the package and no concerning content, there is no evidence of installer-side harm.
{
"malicious-packages-origins": [
{
"id": "RLMA-2026-05434",
"import_time": "2026-07-20T13:14:40.335170147Z",
"modified_time": "2026-07-20T10:22:26Z",
"sha256": "3f20fc0b546aeb9bdc71496f30839ce40239b21a9e133237b35e3f5f28078cba",
"source": "reversing-labs",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-013255",
"import_time": "2026-08-05T06:00:58.849608944Z",
"modified_time": "2026-08-05T05:56:40Z",
"sha256": "525ae6b33885c1153dac485b830c8977b433ba4cdd2cc9556415b146ed801569",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "RLUA-2026-05878",
"import_time": "2026-09-01T11:17:42.212823552Z",
"modified_time": "2026-08-24T16:24:59Z",
"sha256": "c355ce2b7e587ca55ec965d0a97bbee29cb7f51504d715455ee6b4e48dfd99be",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"filename": "odesa-main-1.0.0.tgz",
"hashes": {
"sha1": "e529283b37ccc6b18cfb37cea875cd8e9f395252",
"sha512_sri": "sha512-2YMWvazprxDZm9llz86fJpnAnff/ZWHj+g58Igdpm+yyvvldEoXKLrVeODnA8r1izdD+uw1KpK/KJXXE7hehPg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@irys-solutions/odesa-main/MAL-2026-10881.json"