MAL-2026-1595

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@commonschema/blackstone-core/MAL-2026-1595.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1595
Published
2026-03-18T12:24:55Z
Modified
2026-03-23T05:33:16.653029Z
Summary
Malicious code in @commonschema/blackstone-core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b6f3edc28bea0e512a6dcee373cec98f067d76a64791869cfe843a2434edca05)

The package @commonschema/blackstone-core was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-00977",
            "versions": [
                "0.2.2-alpha",
                "1.0.0",
                "1.0.1",
                "1.0.2",
                "1.0.5",
                "1.0.6",
                "1.0.7",
                "2.0.8"
            ],
            "import_time": "2026-03-19T12:18:23.011807481Z",
            "modified_time": "2026-03-18T12:24:55Z",
            "sha256": "0166499b9e89627c50a22e5e28310e00051b4a3cf7e266a277533cc9ad9900d3"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "0.2.2-alpha",
                "1.0.0",
                "1.0.1",
                "1.0.2",
                "1.0.5",
                "1.0.6",
                "1.0.7",
                "2.0.8"
            ],
            "import_time": "2026-03-23T05:13:58.718112533Z",
            "modified_time": "2026-03-23T05:11:41Z",
            "sha256": "b6f3edc28bea0e512a6dcee373cec98f067d76a64791869cfe843a2434edca05"
        }
    ]
}
References
Credits

Affected packages

npm / @commonschema/blackstone-core

Package

Name
@commonschema/blackstone-core
View open source insights on deps.dev
Purl
pkg:npm/%40commonschema/blackstone-core

Affected ranges

Affected versions

0.*
0.2.2-alpha
1.*
1.0.0
1.0.1
1.0.2
1.0.5
1.0.6
1.0.7
2.*
2.0.8

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@commonschema/blackstone-core/MAL-2026-1595.json"