MAL-2026-2510

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@velora-dex/sdk/MAL-2026-2510.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2510
Published
2026-04-08T04:29:51Z
Modified
2026-04-08T04:50:59.042538Z
Summary
Malicious code in @velora-dex/sdk (npm)
Details

Malicious npm package executing base64-decoded shell command to download and run stage-2 payload from C2 server (89.36.224.5) targeting macOS

Database specific
{
    "malicious-packages-origins": null
}
References
Credits

Affected packages

npm / @velora-dex/sdk

Package

Name
@velora-dex/sdk
View open source insights on deps.dev
Purl
pkg:npm/%40velora-dex/sdk

Affected ranges

Affected versions

9.*
9.4.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@velora-dex/sdk/MAL-2026-2510.json"