MAL-2026-1813

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/phx-core4/MAL-2026-1813.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1813
Published
2026-03-18T13:03:39Z
Modified
2026-03-23T05:44:49.277827Z
Summary
Malicious code in phx-core4 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f34a66abe0d68aa9e9250d5fea5c5a537be067859159164a917c667923d51d0c)

The package phx-core4 was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "8.0.0"
            ],
            "modified_time": "2026-03-18T13:03:39Z",
            "sha256": "a7792525eddb2edeb42a184bbd641478683a9e9d14468afa4debf43f20b6e498",
            "id": "RLMA-2026-01486",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:19:05.18566021Z"
        },
        {
            "versions": [
                "8.0.0"
            ],
            "modified_time": "2026-03-23T05:11:41Z",
            "sha256": "f34a66abe0d68aa9e9250d5fea5c5a537be067859159164a917c667923d51d0c",
            "source": "amazon-inspector",
            "import_time": "2026-03-23T05:14:04.295672469Z"
        }
    ]
}
References
Credits

Affected packages

npm / phx-core4

Package

Affected ranges

Affected versions

8.*
8.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/phx-core4/MAL-2026-1813.json"