MAL-2026-1691

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chromecast-receiver/MAL-2026-1691.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1691
Published
2026-03-18T12:44:06Z
Modified
2026-03-23T05:41:06.199461Z
Summary
Malicious code in chromecast-receiver (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (9ded3cbd70f99d1eeed4d998a82b13da94a22539d5783a36ad7c2651a01ca724)

The package chromecast-receiver was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-01205",
            "versions": [
                "2.0.9",
                "2.0.10"
            ],
            "import_time": "2026-03-19T12:18:42.276707002Z",
            "modified_time": "2026-03-18T12:44:06Z",
            "sha256": "66373fa3570129f6f515b2bf7fdbfa5670ef2ab18bca7e8e9d5f6e4c57ca44b2"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "2.0.9",
                "2.0.10"
            ],
            "import_time": "2026-03-23T05:14:41.808136685Z",
            "modified_time": "2026-03-23T05:11:41Z",
            "sha256": "9ded3cbd70f99d1eeed4d998a82b13da94a22539d5783a36ad7c2651a01ca724"
        }
    ]
}
References
Credits

Affected packages

npm / chromecast-receiver

Package

Name
chromecast-receiver
View open source insights on deps.dev
Purl
pkg:npm/chromecast-receiver

Affected ranges

Affected versions

2.*
2.0.9
2.0.10

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chromecast-receiver/MAL-2026-1691.json"