MAL-2026-2371

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/merchant-rps/MAL-2026-2371.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2371
Published
2026-03-24T15:51:44Z
Modified
2026-04-07T14:54:25.934501Z
Summary
Malicious code in merchant-rps (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d3e16d7a1d2277acd9102268accb99bf0054cf39ee5141d0380f920fedcc8e59)

The package merchant-rps was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-03-24T15:51:44Z",
            "versions": [
                "5.99.99"
            ],
            "sha256": "88254f9068ad87c563475da62e0a5766c0b33149e10b01f3a94011d7a47b01dc",
            "id": "RLMA-2026-01785",
            "source": "reversing-labs",
            "import_time": "2026-04-01T12:26:09.486064895Z"
        },
        {
            "modified_time": "2026-04-07T14:24:50Z",
            "versions": [
                "5.99.99"
            ],
            "sha256": "d3e16d7a1d2277acd9102268accb99bf0054cf39ee5141d0380f920fedcc8e59",
            "source": "amazon-inspector",
            "import_time": "2026-04-07T14:39:08.982038564Z"
        }
    ]
}
References
Credits

Affected packages

npm / merchant-rps

Package

Affected ranges

Affected versions

5.*
5.99.99

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/merchant-rps/MAL-2026-2371.json"