MAL-2026-2388

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/spectral-engine/MAL-2026-2388.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2388
Published
2026-03-24T16:00:10Z
Modified
2026-04-07T14:55:33.360801Z
Summary
Malicious code in spectral-engine (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6d45c9e6ca6d123deeb7d3bfb326dc818f76fb83f256dca70e650842b7cf7620)

The package spectral-engine was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-03-24T16:00:10Z",
            "import_time": "2026-04-01T12:26:10.98511818Z",
            "versions": [
                "2.14.801"
            ],
            "sha256": "36c1776e0c796ae4f47d6e682de1e0e487bb462f0768e5023fd00ec90566ec4e",
            "source": "reversing-labs",
            "id": "RLMA-2026-01816"
        },
        {
            "import_time": "2026-04-07T14:39:16.139350783Z",
            "versions": [
                "2.14.801"
            ],
            "sha256": "6d45c9e6ca6d123deeb7d3bfb326dc818f76fb83f256dca70e650842b7cf7620",
            "source": "amazon-inspector",
            "modified_time": "2026-04-07T14:24:50Z"
        }
    ]
}
References
Credits

Affected packages

npm / spectral-engine

Package

Affected ranges

Affected versions

2.*
2.14.801

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/spectral-engine/MAL-2026-2388.json"