MAL-2026-1775

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/libxmljs2-malicious/MAL-2026-1775.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1775
Published
2026-03-18T12:57:36Z
Modified
2026-03-23T05:43:45.159147Z
Summary
Malicious code in libxmljs2-malicious (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (392c5138d36ba42a009c8a27d8f4c158141a814c9990c022b422f540945e71e5)

The package libxmljs2-malicious was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-01408",
            "sha256": "87b34082739a2c515181d5f404ff3092a7f29a538702fdc69dc2a8d5ad002965",
            "import_time": "2026-03-19T12:18:59.313964573Z",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:57:36Z",
            "versions": [
                "0.19.9"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:38.984135106Z",
            "sha256": "392c5138d36ba42a009c8a27d8f4c158141a814c9990c022b422f540945e71e5",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "0.19.9"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / libxmljs2-malicious

Package

Name
libxmljs2-malicious
View open source insights on deps.dev
Purl
pkg:npm/libxmljs2-malicious

Affected ranges

Affected versions

0.*
0.19.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/libxmljs2-malicious/MAL-2026-1775.json"