MAL-2026-1759

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/karem2/MAL-2026-1759.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1759
Published
2026-03-18T12:56:37Z
Modified
2026-03-23T05:43:31.750922Z
Summary
Malicious code in karem2 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7a920bfa0aa3642b248e4edf2074e57fae07f08c8824a4bc57ebd7063459559b)

The package karem2 was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-01385",
            "import_time": "2026-03-19T12:18:57.188928567Z",
            "sha256": "760767732b0cb6dc257287e0cfe8b9a8f7f3db8021ae98bae226a3435b1bf407",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:56:37Z",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:03.071140619Z",
            "sha256": "7a920bfa0aa3642b248e4edf2074e57fae07f08c8824a4bc57ebd7063459559b",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / karem2

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/karem2/MAL-2026-1759.json"