MAL-2026-1495

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/whatfix-icons/MAL-2026-1495.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1495
Published
2026-03-17T06:25:55Z
Modified
2026-03-23T05:37:35.729734Z
Summary
Malicious code in whatfix-icons (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (003442c235ba313d832b958d8170e59f28d9af34abdd1f33a832c6c2cd263696)

The package whatfix-icons was found to contain malicious code.

Source: ossf-package-analysis (a857b749803a6f06804b11242567a486660d84a4fe6f59f0da412f064da7ad1e)

The OpenSSF Package Analysis project identified 'whatfix-icons' @ 99.1.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "versions": [
                "7.0.0"
            ],
            "import_time": "2026-03-17T06:28:32.175193465Z",
            "modified_time": "2026-03-17T06:25:55Z",
            "sha256": "2fd3f069f3ec6f8384266ab436e53c9f43c1705b8938dad1ce464fea51591609"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "99.1.0"
            ],
            "import_time": "2026-03-17T08:19:57.165778064Z",
            "modified_time": "2026-03-17T07:55:48Z",
            "sha256": "a857b749803a6f06804b11242567a486660d84a4fe6f59f0da412f064da7ad1e"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "7.0.0",
                "99.1.0"
            ],
            "import_time": "2026-03-23T05:14:25.952429715Z",
            "modified_time": "2026-03-23T05:11:41Z",
            "sha256": "003442c235ba313d832b958d8170e59f28d9af34abdd1f33a832c6c2cd263696"
        }
    ]
}
References
Credits

Affected packages

npm / whatfix-icons

Package

Affected ranges

Affected versions

7.*
7.0.0
99.*
99.1.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/whatfix-icons/MAL-2026-1495.json"