MAL-2026-2437

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exaprse/MAL-2026-2437.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2437
Published
2026-04-02T15:12:58Z
Modified
2026-04-07T14:53:20.273126Z
Summary
Malicious code in exaprse (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c6cac7f3a62099b4980a3948c78a3a231085dece3eac1d5ca3aa0bc3b0d102e5)

The package exaprse was found to contain malicious code.

Source: ossf-package-analysis (e6b772ab3336f1923332b7f4042b5daa8ea5fdef08b605e35f6410c40f6a257f)

The OpenSSF Package Analysis project identified 'exaprse' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-03T05:59:53.455806319Z",
            "versions": [
                "1.0.0"
            ],
            "sha256": "e6b772ab3336f1923332b7f4042b5daa8ea5fdef08b605e35f6410c40f6a257f",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-02T15:12:58Z"
        },
        {
            "import_time": "2026-04-07T14:39:12.1491477Z",
            "versions": [
                "1.0.0"
            ],
            "sha256": "c6cac7f3a62099b4980a3948c78a3a231085dece3eac1d5ca3aa0bc3b0d102e5",
            "source": "amazon-inspector",
            "modified_time": "2026-04-07T14:24:50Z"
        }
    ]
}
References
Credits

Affected packages

npm / exaprse

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exaprse/MAL-2026-2437.json"