MAL-2026-2331

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@girirajravichandran/corp-build-utils-poc/MAL-2026-2331.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2331
Published
2026-03-24T15:28:29Z
Modified
2026-04-16T15:50:58.996453Z
Summary
Malicious code in @girirajravichandran/corp-build-utils-poc (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (82e79f342b1cd33520c8987b0307cb211e4b04694caef9c967725778e1802e94)

The package @girirajravichandran/corp-build-utils-poc was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "c3fd3c6573713ac03147f039d38fa6d43614996bc6f3ad44007c31bf5b41ab53",
            "id": "RLMA-2026-01695",
            "source": "reversing-labs",
            "modified_time": "2026-03-24T15:28:29Z",
            "versions": [
                "99.9.29"
            ],
            "import_time": "2026-04-01T12:26:06.247629779Z"
        },
        {
            "sha256": "82e79f342b1cd33520c8987b0307cb211e4b04694caef9c967725778e1802e94",
            "import_time": "2026-04-07T14:39:09.494257528Z",
            "source": "amazon-inspector",
            "modified_time": "2026-04-07T14:24:50Z",
            "versions": [
                "99.9.29"
            ]
        },
        {
            "sha256": "f2ca2d526cc484891da34c40490d46c6419c48971ba4ea0930f114f4a03962b1",
            "id": "RLUA-2026-01856",
            "source": "reversing-labs",
            "modified_time": "2026-04-16T09:34:12Z",
            "versions": [
                "99.9.31"
            ],
            "import_time": "2026-04-16T15:39:24.173346657Z"
        }
    ]
}
References
Credits

Affected packages

npm / @girirajravichandran/corp-build-utils-poc

Package

Name
@girirajravichandran/corp-build-utils-poc
View open source insights on deps.dev
Purl
pkg:npm/%40girirajravichandran/corp-build-utils-poc

Affected ranges

Affected versions

99.*
99.9.29
99.9.31

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@girirajravichandran/corp-build-utils-poc/MAL-2026-2331.json"