MAL-2026-1737

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fe-lib-theme/MAL-2026-1737.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1737
Published
2026-03-18T12:51:11Z
Modified
2026-03-23T05:42:21.078808Z
Summary
Malicious code in fe-lib-theme (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fc3834e7b034601a3ed7f032e0575770c41742c9f13761e0e79ced9c7893af86)

The package fe-lib-theme was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-01316",
            "sha256": "e7676da81020b331aaabc74b98b2b863804f97137e43cb93cc2784d015a608b0",
            "import_time": "2026-03-19T12:18:52.165928094Z",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:51:11Z",
            "versions": [
                "99.99.9",
                "99.99.99",
                "999.999.999"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:31.517868828Z",
            "sha256": "fc3834e7b034601a3ed7f032e0575770c41742c9f13761e0e79ced9c7893af86",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "99.99.9",
                "99.99.99",
                "999.999.999"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / fe-lib-theme

Package

Affected ranges

Affected versions

99.*
99.99.9
99.99.99
999.*
999.999.999

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fe-lib-theme/MAL-2026-1737.json"