MAL-2026-1878

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wpt-client/MAL-2026-1878.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1878
Published
2026-03-18T13:16:24Z
Modified
2026-03-23T05:42:34.926581Z
Summary
Malicious code in wpt-client (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6928aebd6d492c4618abb9136b97cdf065cf37f91fab0e0a11a5688cd0e4f5f7)

The package wpt-client was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-03-18T13:16:24Z",
            "versions": [
                "100.0.0"
            ],
            "sha256": "ca6797001232d5a2910d8be0ed981901d842c5262722b32a0a1b98b79e9ebe1d",
            "id": "RLMA-2026-01653",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:19:16.147803921Z"
        },
        {
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "100.0.0"
            ],
            "sha256": "6928aebd6d492c4618abb9136b97cdf065cf37f91fab0e0a11a5688cd0e4f5f7",
            "source": "amazon-inspector",
            "import_time": "2026-03-23T05:14:12.610894365Z"
        }
    ]
}
References
Credits

Affected packages

npm / wpt-client

Package

Affected ranges

Affected versions

100.*
100.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wpt-client/MAL-2026-1878.json"