MAL-2026-2345

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/codecoverage-tools/MAL-2026-2345.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2345
Published
2026-03-24T15:40:45Z
Modified
2026-04-07T14:50:47.674178Z
Summary
Malicious code in codecoverage-tools (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (77e8adaf551291b58aa99518bd0d9c4817709eb0e987acb0f318405926c8f6a1)

The package codecoverage-tools was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-01T12:26:07.366731885Z",
            "versions": [
                "1.0.1",
                "1.0.2"
            ],
            "source": "reversing-labs",
            "id": "RLMA-2026-01731",
            "modified_time": "2026-03-24T15:40:45Z",
            "sha256": "72c13dbd1852d2063bbfbbb0b2b78084c5a54d6a688adf9aeea196bc3936f3c6"
        },
        {
            "import_time": "2026-04-07T14:39:15.934411229Z",
            "versions": [
                "1.0.1",
                "1.0.2"
            ],
            "sha256": "77e8adaf551291b58aa99518bd0d9c4817709eb0e987acb0f318405926c8f6a1",
            "modified_time": "2026-04-07T14:24:50Z",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / codecoverage-tools

Package

Affected ranges

Affected versions

1.*
1.0.1
1.0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/codecoverage-tools/MAL-2026-2345.json"