MAL-2026-2235

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/srcsrctest/MAL-2026-2235.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2235
Published
2026-03-26T12:05:48Z
Modified
2026-03-31T03:24:52.090869Z
Summary
Malicious code in srcsrctest (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a44b46855732b5a5522c0a1ea3ef88d5977daad1bfa5c39b42e0324e52fcf6f8)

The package srcsrctest was found to contain malicious code.

Source: ossf-package-analysis (1aa147cd1bafdb2bf26b1c157edac9d3765ce544456e7f4e0fde95cd269af777)

The OpenSSF Package Analysis project identified 'srcsrctest' @ 1.0.6 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "1aa147cd1bafdb2bf26b1c157edac9d3765ce544456e7f4e0fde95cd269af777",
            "import_time": "2026-03-26T12:25:46.32136861Z",
            "modified_time": "2026-03-26T12:15:48Z",
            "versions": [
                "1.0.6"
            ],
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "9049c460c15f43120e5e8bb1207b5a642536124c66ff3dc7863e679e9d46b26e",
            "import_time": "2026-03-26T12:25:46.220899442Z",
            "modified_time": "2026-03-26T12:05:48Z",
            "versions": [
                "1.0.3"
            ],
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "a44b46855732b5a5522c0a1ea3ef88d5977daad1bfa5c39b42e0324e52fcf6f8",
            "import_time": "2026-03-31T03:10:11.122342903Z",
            "modified_time": "2026-03-31T02:07:58Z",
            "versions": [
                "1.0.6",
                "1.0.3"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / srcsrctest

Package

Affected ranges

Affected versions

1.*
1.0.3
1.0.6

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/srcsrctest/MAL-2026-2235.json"