MAL-2026-1696

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/components-design-system/MAL-2026-1696.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1696
Published
2026-03-18T12:44:37Z
Modified
2026-03-23T05:41:13.560132Z
Summary
Malicious code in components-design-system (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ca129c441caef97d904867f91617f53799650e2f2deef3f531a3a18dfc917efa)

The package components-design-system was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-03-18T12:44:37Z",
            "versions": [
                "99.99.99"
            ],
            "sha256": "b0f5d9ea6589e0418d43c00241332f243eb07ccb8cd5d4cdf61dc00a551cfd36",
            "id": "RLMA-2026-01214",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:18:42.972978255Z"
        },
        {
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "99.99.99"
            ],
            "sha256": "ca129c441caef97d904867f91617f53799650e2f2deef3f531a3a18dfc917efa",
            "source": "amazon-inspector",
            "import_time": "2026-03-23T05:14:15.240883594Z"
        }
    ]
}
References
Credits

Affected packages

npm / components-design-system

Package

Name
components-design-system
View open source insights on deps.dev
Purl
pkg:npm/components-design-system

Affected ranges

Affected versions

99.*
99.99.99

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/components-design-system/MAL-2026-1696.json"