MAL-2026-2014

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/address-autocompletetest/MAL-2026-2014.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2014
Published
2026-03-21T15:30:37Z
Modified
2026-03-23T05:39:25.341052Z
Summary
Malicious code in address-autocompletetest (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b797224d264945b820a632a44fdf26c3baa54e8f1b5f6fe3db4a1739ee726f58)

The package address-autocompletetest was found to contain malicious code.

Source: ossf-package-analysis (3cba808ae68c1f7fb09edff59a151d9a9ff4253dad6f40ab15767fbf5273482f)

The OpenSSF Package Analysis project identified 'address-autocompletetest' @ 99.3.380452 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-03-21T15:41:06.045330561Z",
            "sha256": "3cba808ae68c1f7fb09edff59a151d9a9ff4253dad6f40ab15767fbf5273482f",
            "source": "ossf-package-analysis",
            "modified_time": "2026-03-21T15:30:37Z",
            "versions": [
                "99.3.380452"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:24.708905417Z",
            "sha256": "b797224d264945b820a632a44fdf26c3baa54e8f1b5f6fe3db4a1739ee726f58",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "99.3.380452"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / address-autocompletetest

Package

Name
address-autocompletetest
View open source insights on deps.dev
Purl
pkg:npm/address-autocompletetest

Affected ranges

Affected versions

99.*
99.3.380452

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/address-autocompletetest/MAL-2026-2014.json"