MAL-2026-2378

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/node-multer/MAL-2026-2378.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2378
Published
2026-03-24T15:53:26Z
Modified
2026-04-07T14:54:49.398190Z
Summary
Malicious code in node-multer (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6fd13a20e1e6edfd702b510f8205a60c9826a214ac27b04e1c6b48dee5f74d76)

The package node-multer was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-01797",
            "versions": [
                "3.5.7"
            ],
            "import_time": "2026-04-01T12:26:10.14613923Z",
            "modified_time": "2026-03-24T15:53:26Z",
            "sha256": "ac071000b6c869ddf4dffecfb76b05cbab824a6ca662eacf05f6b0ad492616bc"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "3.5.7"
            ],
            "import_time": "2026-04-07T14:39:10.050291054Z",
            "modified_time": "2026-04-07T14:24:50Z",
            "sha256": "6fd13a20e1e6edfd702b510f8205a60c9826a214ac27b04e1c6b48dee5f74d76"
        }
    ]
}
References
Credits

Affected packages

npm / node-multer

Package

Affected ranges

Affected versions

3.*
3.5.7

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/node-multer/MAL-2026-2378.json"