MAL-2026-14116

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/runtime-health/MAL-2026-14116.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14116
Published
2026-08-17T08:36:14Z
Modified
2026-08-18T01:00:11.727878319Z
Summary
Malicious code in runtime-health (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (947c67500453c29daa330afc7d05e5ab5eb6405c4da235d1d0b408b247489832)

The OpenSSF Package Analysis project identified 'runtime-health' @ 1.0.2 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-18T00:51:31.696673767Z",
            "source": "ossf-package-analysis",
            "modified_time": "2026-08-17T08:50:58Z",
            "sha256": "947c67500453c29daa330afc7d05e5ab5eb6405c4da235d1d0b408b247489832",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "import_time": "2026-08-18T00:51:31.55440432Z",
            "sha256": "d9e71daa18c5918df751c2c556f352736fefba535c8ed612faed227ebd8eda40",
            "modified_time": "2026-08-17T09:56:04Z",
            "source": "ossf-package-analysis",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "import_time": "2026-08-18T00:51:31.787214358Z",
            "sha256": "dd172704e1a61ef5a2a016258136478465a1bd13cd3c5a2b697a2c9b76078afc",
            "modified_time": "2026-08-17T08:36:14Z",
            "source": "ossf-package-analysis",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / runtime-health

Package

Affected ranges

Affected versions

1.*
1.0.1
1.0.2
1.0.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/runtime-health/MAL-2026-14116.json"