MAL-2026-1693

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/coinbase-desktop-sdk/MAL-2026-1693.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1693
Published
2026-03-18T12:44:21Z
Modified
2026-04-16T15:53:53.234093Z
Summary
Malicious code in coinbase-desktop-sdk (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5acc3fd93737f0c91c26014273ad41b78393a11a3c9377a337636ce2ba558477)

The package coinbase-desktop-sdk was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-01211",
            "versions": [
                "1.5.14",
                "1.5.15",
                "1.5.16",
                "1.5.17",
                "1.5.19"
            ],
            "import_time": "2026-03-19T12:18:42.634777406Z",
            "modified_time": "2026-03-18T12:44:21Z",
            "sha256": "8cf806b4effa415af57ef60eb1b36074b399696799b34c4afde377177331c402"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "1.5.14",
                "1.5.15",
                "1.5.16",
                "1.5.17",
                "1.5.19"
            ],
            "import_time": "2026-03-23T05:14:31.214249475Z",
            "modified_time": "2026-03-23T05:11:41Z",
            "sha256": "5acc3fd93737f0c91c26014273ad41b78393a11a3c9377a337636ce2ba558477"
        },
        {
            "source": "reversing-labs",
            "id": "RLUA-2026-01926",
            "import_time": "2026-04-16T15:39:27.25787983Z",
            "modified_time": "2026-04-16T09:50:05Z",
            "sha256": "7bfe656aa67bbceeed2d7f6def21d5c20f9ec1f22d4cab7ba113021174933e08"
        }
    ]
}
References
Credits

Affected packages

npm / coinbase-desktop-sdk

Package

Name
coinbase-desktop-sdk
View open source insights on deps.dev
Purl
pkg:npm/coinbase-desktop-sdk

Affected ranges

Affected versions

1.*
1.5.14
1.5.15
1.5.16
1.5.17
1.5.19

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/coinbase-desktop-sdk/MAL-2026-1693.json"