-= Per source details. Do not edit below this line.=-
package.json declares a dependency sourced from a git URL (git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git) pinned to commit 0abd2c55e475f12f58fb67ac487db4c1b00cf597, rather than from the npm registry. On npm install, npm clones that GitHub repository and runs any lifecycle scripts it contains, including a prepare hook indicated by the dependency's name. The dependency source is an individual GitHub account (agustedone/...) unrelated to any established publisher, and the fetched code is not subject to npm registry review or integrity checks against a registry tarball. Whoever controls that GitHub repository controls code executed on the installer's machine at install time.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020791",
"import_time": "2026-09-30T02:52:56.663772057Z",
"modified_time": "2026-09-30T01:47:10Z",
"sha256": "4088f6f05dc6a2187563d3b6e47047d7206446a8642bb62d2cc2c27347418e70",
"source": "amazon-inspector",
"versions": [
"3.3.3"
]
},
{
"id": "IN-MAL-2026-020790",
"import_time": "2026-09-30T02:52:56.544764263Z",
"modified_time": "2026-09-30T01:47:02Z",
"sha256": "80bcbaa6379206627641c70dd25da3c3adfd51337f9a378223a6f8f13c8ba3ed",
"source": "amazon-inspector",
"versions": [
"3.3.4"
]
},
{
"id": "IN-MAL-2026-020820",
"import_time": "2026-09-30T05:44:17.304955595Z",
"modified_time": "2026-09-30T05:30:46Z",
"sha256": "3eae72a7bc74450d855cd61f154508a7b6e1419095c8d3c88c32f3e81b77b3af",
"source": "amazon-inspector",
"versions": [
"3.3.6"
]
},
{
"id": "IN-MAL-2026-020821",
"import_time": "2026-09-30T05:44:17.334402313Z",
"modified_time": "2026-09-30T05:30:56Z",
"sha256": "44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268",
"source": "amazon-inspector",
"versions": [
"3.3.5"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "8d90884a76b25c576aecaa0b096d8c7c1d8d934e8c6ac6e11501bc18b6adfc06",
"tlsh": "48e05c60d6210c7728c129f0cc613443ff518c234464ad053793516dce491bb40fd63f"
}
],
"package_integrity": [
{
"filename": "test-supply-npm-lib-4-3.3.3.tgz",
"hashes": {
"sha1": "e350fa83bf9607ab65feda3190e2d7d1bc4fd99e",
"sha512_sri": "sha512-BhsR8kcp0u4pNt6yZ/RiP46Xt2hUNuBZreE1lghxVuCLPV3+CNO1lbgVLlaM27uxYEC4evcfDdVjK4nP+5tGSA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-supply-npm-lib-4/MAL-2026-17314.json"