MAL-2026-11069

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/clerk-next-fix-auth-protection/MAL-2026-11069.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11069
Published
2026-07-24T21:48:05Z
Modified
2026-07-27T02:07:25.717303018Z
Summary
Malicious code in clerk-next-fix-auth-protection (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6)

The OpenSSF Package Analysis project identified 'clerk-next-fix-auth-protection' @ 8.8.8 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6",
            "versions": [
                "8.8.8"
            ],
            "modified_time": "2026-07-24T21:48:05Z",
            "import_time": "2026-07-27T01:42:44.34274726Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "237107ad75c2e23fe27919d8b194c3ce7b4048e31db18b7b2d280d4f1e0cf0e8",
            "versions": [
                "7.7.7"
            ],
            "modified_time": "2026-07-24T21:55:38Z",
            "import_time": "2026-07-27T01:42:44.241881516Z",
            "source": "ossf-package-analysis"
        }
    ]
}
References
Credits

Affected packages

npm / clerk-next-fix-auth-protection

Package

Name
clerk-next-fix-auth-protection
View open source insights on deps.dev
Purl
pkg:npm/clerk-next-fix-auth-protection

Affected ranges

Affected versions

7.*
7.7.7
8.*
8.8.8

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/clerk-next-fix-auth-protection/MAL-2026-11069.json"