MAL-2026-2435

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/4xperss/MAL-2026-2435.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2435
Published
2026-04-02T15:12:23Z
Modified
2026-04-07T14:51:16.447389Z
Summary
Malicious code in 4xperss (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6de1a8af1dbe21de2e06785a6a5e41a438f356fe440c8b121b808975ef95f5fe)

The package 4xperss was found to contain malicious code.

Source: ossf-package-analysis (d8cb27dbe58e29571ce6b777903222af9497b79676e8301021d03f159c5d77ae)

The OpenSSF Package Analysis project identified '4xperss' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-03T05:59:53.798281099Z",
            "sha256": "d8cb27dbe58e29571ce6b777903222af9497b79676e8301021d03f159c5d77ae",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-02T15:12:23Z",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "import_time": "2026-04-07T14:39:10.441782397Z",
            "sha256": "6de1a8af1dbe21de2e06785a6a5e41a438f356fe440c8b121b808975ef95f5fe",
            "source": "amazon-inspector",
            "modified_time": "2026-04-07T14:24:50Z",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / 4xperss

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/4xperss/MAL-2026-2435.json"