MAL-2026-1743

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/haodesk-ui/MAL-2026-1743.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1743
Published
2026-03-18T12:53:39Z
Modified
2026-03-23T05:42:36.109004Z
Summary
Malicious code in haodesk-ui (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d84a56e7e332520633c65a2690e70d5eb4792907c98da8a7d6830a463438c7d2)

The package haodesk-ui was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-03-18T12:53:39Z",
            "import_time": "2026-03-19T12:18:54.312680366Z",
            "versions": [
                "4.0.2"
            ],
            "sha256": "87c47ddc093ed1405e09d234115b8c8045921f5db25f4559a97589bdd6b469f8",
            "source": "reversing-labs",
            "id": "RLMA-2026-01341"
        },
        {
            "import_time": "2026-03-23T05:14:19.314830488Z",
            "versions": [
                "4.0.2"
            ],
            "sha256": "d84a56e7e332520633c65a2690e70d5eb4792907c98da8a7d6830a463438c7d2",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z"
        }
    ]
}
References
Credits

Affected packages

npm / haodesk-ui

Package

Affected ranges

Affected versions

4.*
4.0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/haodesk-ui/MAL-2026-1743.json"