MAL-2026-2492

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/admin0911/MAL-2026-2492.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2492
Published
2026-04-05T15:30:57Z
Modified
2026-04-05T19:02:38.309091Z
Summary
Malicious code in admin0911 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (5c85e038183d5abde236e2f52464a662b6aed5f6129c6ad6a568ec565c361f89)

The OpenSSF Package Analysis project identified 'admin0911' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.0.1"
            ],
            "import_time": "2026-04-05T15:44:59.807607857Z",
            "modified_time": "2026-04-05T15:43:43Z",
            "sha256": "3695d0f7489e83b4ec745cea51d9a057efc6c22f3f7a4b2fb6e640527d8343a4",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-04-05T15:44:59.662404516Z",
            "modified_time": "2026-04-05T15:30:57Z",
            "sha256": "5c85e038183d5abde236e2f52464a662b6aed5f6129c6ad6a568ec565c361f89",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.2"
            ],
            "import_time": "2026-04-05T15:44:59.753649986Z",
            "modified_time": "2026-04-05T15:39:31Z",
            "sha256": "e18d7245ffba525783ef5adcf4e1139bbab811212ba167258d6b1c41462a3356",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.5"
            ],
            "import_time": "2026-04-05T16:12:37.953107833Z",
            "modified_time": "2026-04-05T16:10:09Z",
            "sha256": "5400638b8f302ba0dcdf7fe2ef807b7d914e1402f7c26109b3b68e2b46af7ffd",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.4"
            ],
            "import_time": "2026-04-05T16:12:37.901744722Z",
            "modified_time": "2026-04-05T15:55:48Z",
            "sha256": "26fac17d4076abe58d460e1e9ceaedeec2f6ba9e3daaaf1920dd84caa638a32e",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.8"
            ],
            "import_time": "2026-04-05T17:12:27.682975085Z",
            "modified_time": "2026-04-05T16:55:37Z",
            "sha256": "cf656bb5a4d98071f7a8ab56f208cd3700efe87a7325c344eb379d8e87d8e139",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.12"
            ],
            "import_time": "2026-04-05T17:45:11.355907433Z",
            "modified_time": "2026-04-05T17:34:39Z",
            "sha256": "428a4a04a4930c8c8d9b430fb7a3ffcff1dd4cd2cbf63727ccaf9d3c8de48936",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.11"
            ],
            "import_time": "2026-04-05T17:45:11.274943083Z",
            "modified_time": "2026-04-05T17:32:00Z",
            "sha256": "382bdef35e36a5feec0cad981c76915cb8f875d01626bd3395bedb729e9b0486",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.10"
            ],
            "import_time": "2026-04-05T18:14:53.614474406Z",
            "modified_time": "2026-04-05T17:46:16Z",
            "sha256": "e5e4e1fc75301ca7250ef6fced097b98d827424f1df7f2ef4a1dfe0405ec39f0",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.14"
            ],
            "import_time": "2026-04-05T18:48:11.019127717Z",
            "modified_time": "2026-04-05T18:38:39Z",
            "sha256": "09f24ddbbcc8473b6871c3da3e69e669df9b7f643bfac2dd4b582e5962c4eecd",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "1.0.13"
            ],
            "import_time": "2026-04-05T18:48:10.851779219Z",
            "modified_time": "2026-04-05T18:35:52Z",
            "sha256": "4faf70dade9278166dd051dda6a1a3c8bf87c810b0d206830f118dedf2ba3448",
            "source": "ossf-package-analysis"
        }
    ]
}
References
Credits

Affected packages

npm / admin0911

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.4
1.0.5
1.0.8
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/admin0911/MAL-2026-2492.json"