MAL-2026-1821

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/portal-lime/MAL-2026-1821.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1821
Published
2026-03-18T13:04:20Z
Modified
2026-03-23T05:45:01.331146Z
Summary
Malicious code in portal-lime (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a61d5bfbd22f203a4a68f3329504312a967221d510ce7ceed02c663b0de8e002)

The package portal-lime was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "2.1.3"
            ],
            "modified_time": "2026-03-18T13:04:20Z",
            "sha256": "94381de623a657a017a0aad90e1c1b94f136b9eaa164e3a6f743263944139dd4",
            "id": "RLMA-2026-01501",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:19:06.438487022Z"
        },
        {
            "versions": [
                "2.1.3"
            ],
            "modified_time": "2026-03-23T05:11:41Z",
            "sha256": "a61d5bfbd22f203a4a68f3329504312a967221d510ce7ceed02c663b0de8e002",
            "source": "amazon-inspector",
            "import_time": "2026-03-23T05:14:27.146895349Z"
        }
    ]
}
References
Credits

Affected packages

npm / portal-lime

Package

Affected ranges

Affected versions

2.*
2.1.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/portal-lime/MAL-2026-1821.json"