MAL-2026-1705

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dazz-redirects/MAL-2026-1705.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1705
Published
2026-03-18T12:46:07Z
Modified
2026-03-23T05:41:39.817483Z
Summary
Malicious code in dazz-redirects (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (8bb7f0fb09aa6ba372227ff0fc3cfc80e28c609fc7b2e9c22965972f9771a988)

The package dazz-redirects was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "6ea3eefb7afa1b3c7dbb2fc7a9d073de3ddc9f807364d91caf4ed14df8cff5ed",
            "import_time": "2026-03-19T12:18:44.679297099Z",
            "modified_time": "2026-03-18T12:46:07Z",
            "versions": [
                "1.0.0",
                "1.0.1",
                "4.10.1",
                "4.10.2",
                "4.10.3",
                "4.10.4",
                "4.10.5",
                "4.10.6",
                "4.10.7",
                "4.10.8",
                "4.10.9",
                "4.10.10",
                "4.10.11",
                "4.10.12",
                "4.10.13",
                "4.10.14",
                "4.10.15",
                "4.10.16",
                "4.10.17",
                "4.10.18",
                "4.10.19",
                "4.10.20",
                "4.10.21",
                "4.10.22",
                "4.10.23",
                "4.10.24",
                "4.10.25",
                "4.10.26",
                "4.10.27",
                "4.10.28",
                "4.10.29",
                "4.10.30",
                "4.10.31",
                "4.10.32",
                "4.10.33",
                "4.10.34",
                "4.10.35",
                "4.10.36",
                "4.10.37",
                "4.10.38",
                "4.10.39",
                "4.10.43",
                "4.10.45",
                "4.10.46",
                "4.10.50",
                "4.10.52",
                "4.10.53",
                "4.10.55",
                "4.10.57",
                "4.10.58",
                "4.10.59",
                "4.10.61",
                "4.10.63",
                "4.10.66",
                "4.10.67",
                "4.10.68",
                "4.10.69",
                "4.10.70",
                "4.10.74",
                "4.10.77",
                "4.10.78",
                "4.10.80",
                "4.10.82",
                "4.10.86",
                "4.10.89",
                "4.10.93",
                "4.10.95",
                "4.10.96",
                "99.999.99"
            ],
            "id": "RLMA-2026-01236",
            "source": "reversing-labs"
        },
        {
            "sha256": "8bb7f0fb09aa6ba372227ff0fc3cfc80e28c609fc7b2e9c22965972f9771a988",
            "import_time": "2026-03-23T05:14:06.012013077Z",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "1.0.0",
                "1.0.1",
                "4.10.1",
                "4.10.2",
                "4.10.3",
                "4.10.4",
                "4.10.5",
                "4.10.6",
                "4.10.7",
                "4.10.8",
                "4.10.9",
                "4.10.10",
                "4.10.11",
                "4.10.12",
                "4.10.13",
                "4.10.14",
                "4.10.15",
                "4.10.16",
                "4.10.17",
                "4.10.18",
                "4.10.19",
                "4.10.20",
                "4.10.21",
                "4.10.22",
                "4.10.23",
                "4.10.24",
                "4.10.25",
                "4.10.26",
                "4.10.27",
                "4.10.28",
                "4.10.29",
                "4.10.30",
                "4.10.31",
                "4.10.32",
                "4.10.33",
                "4.10.34",
                "4.10.35",
                "4.10.36",
                "4.10.37",
                "4.10.38",
                "4.10.39",
                "4.10.43",
                "4.10.45",
                "4.10.46",
                "4.10.50",
                "4.10.52",
                "4.10.53",
                "4.10.55",
                "4.10.57",
                "4.10.58",
                "4.10.59",
                "4.10.61",
                "4.10.63",
                "4.10.66",
                "4.10.67",
                "4.10.68",
                "4.10.69",
                "4.10.70",
                "4.10.74",
                "4.10.77",
                "4.10.78",
                "4.10.80",
                "4.10.82",
                "4.10.86",
                "4.10.89",
                "4.10.93",
                "4.10.95",
                "4.10.96",
                "99.999.99"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / dazz-redirects

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
4.*
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.10.7
4.10.8
4.10.9
4.10.10
4.10.11
4.10.12
4.10.13
4.10.14
4.10.15
4.10.16
4.10.17
4.10.18
4.10.19
4.10.20
4.10.21
4.10.22
4.10.23
4.10.24
4.10.25
4.10.26
4.10.27
4.10.28
4.10.29
4.10.30
4.10.31
4.10.32
4.10.33
4.10.34
4.10.35
4.10.36
4.10.37
4.10.38
4.10.39
4.10.43
4.10.45
4.10.46
4.10.50
4.10.52
4.10.53
4.10.55
4.10.57
4.10.58
4.10.59
4.10.61
4.10.63
4.10.66
4.10.67
4.10.68
4.10.69
4.10.70
4.10.74
4.10.77
4.10.78
4.10.80
4.10.82
4.10.86
4.10.89
4.10.93
4.10.95
4.10.96
99.*
99.999.99

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dazz-redirects/MAL-2026-1705.json"