MAL-2026-1857

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/stnsxmp/MAL-2026-1857.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1857
Published
2026-03-18T13:10:55Z
Modified
2026-03-23T05:46:04.543150Z
Summary
Malicious code in stnsxmp (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6f71046374980b35d68230cf391bf580cd1ce68017bf6ac6373b72b01b9d9b67)

The package stnsxmp was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-01592",
            "import_time": "2026-03-19T12:19:12.017258587Z",
            "sha256": "ae3ea08bd0db07c366055b6edb3ab7ea69823fd665c2443527fbb6f44af8e9ec",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T13:10:55Z",
            "versions": [
                "0.0.1",
                "0.30.1"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:13.387757793Z",
            "sha256": "6f71046374980b35d68230cf391bf580cd1ce68017bf6ac6373b72b01b9d9b67",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "0.0.1",
                "0.30.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / stnsxmp

Package

Affected ranges

Affected versions

0.*
0.0.1
0.30.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/stnsxmp/MAL-2026-1857.json"