MAL-2026-2285

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dial-app-version/MAL-2026-2285.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2285
Published
2026-03-29T10:58:29Z
Modified
2026-03-31T03:23:37.999180Z
Summary
Malicious code in dial-app-version (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (9efdd5b481d49a0d9ac535aedde75dbf5638bd85e7efe9c536d2938c57142799)

The package dial-app-version was found to contain malicious code.

Source: ossf-package-analysis (2708b4f6c8fba40d24ccf0abe6369cb348897b35a070092f0b8b4ac45f651059)

The OpenSSF Package Analysis project identified 'dial-app-version' @ 9999.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-03-29T11:00:56Z",
            "versions": [
                "9999.0.1"
            ],
            "sha256": "2708b4f6c8fba40d24ccf0abe6369cb348897b35a070092f0b8b4ac45f651059",
            "source": "ossf-package-analysis",
            "import_time": "2026-03-29T11:11:25.645815498Z"
        },
        {
            "modified_time": "2026-03-29T10:58:29Z",
            "versions": [
                "9999.0.0"
            ],
            "sha256": "f8fbff38278c58a342e8a680f69fd75ac3ec1e9a857f32ec05d0b6ce2cf6bdd0",
            "source": "ossf-package-analysis",
            "import_time": "2026-03-29T11:11:25.572502529Z"
        },
        {
            "modified_time": "2026-03-29T11:33:27Z",
            "versions": [
                "9999.0.3"
            ],
            "sha256": "3d1620a1a42d35263cdd75a5fd74af426073d4eb368227e4378ca821c31a0c37",
            "source": "ossf-package-analysis",
            "import_time": "2026-03-29T11:42:24.47351048Z"
        },
        {
            "modified_time": "2026-03-31T02:07:58Z",
            "versions": [
                "9999.0.1",
                "9999.0.0",
                "9999.0.3"
            ],
            "sha256": "9efdd5b481d49a0d9ac535aedde75dbf5638bd85e7efe9c536d2938c57142799",
            "source": "amazon-inspector",
            "import_time": "2026-03-31T03:10:04.980722181Z"
        }
    ]
}
References
Credits

Affected packages

npm / dial-app-version

Package

Affected ranges

Affected versions

9999.*
9999.0.0
9999.0.1
9999.0.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dial-app-version/MAL-2026-2285.json"