MAL-2026-2510

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@velora-dex/sdk/MAL-2026-2510.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2510
Published
2026-04-07T19:23:02Z
Modified
2026-04-20T01:06:39.306649Z
Summary
Malicious code in @velora-dex/sdk (npm)
Details

Malicious npm package executing base64-decoded shell command to download and run stage-2 payload from C2 server (89.36.224.5) targeting macOS


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (21a732dd2745098176d2c19fe3edb359db6f6690b5d14b8d49e8a00b61325311)

The package @velora-dex/sdk was found to contain malicious code.

Source: ossf-package-analysis (013b2c71633a40b8d425f998bb589074e403eea3069a0af42d70a041827475a3)

The OpenSSF Package Analysis project identified '@velora-dex/sdk' @ 9.4.1 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "versions": [
                "9.4.1"
            ],
            "import_time": "2026-04-10T17:21:50.564186301Z",
            "modified_time": "2026-04-10T17:02:58Z",
            "sha256": "21a732dd2745098176d2c19fe3edb359db6f6690b5d14b8d49e8a00b61325311"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "9.4.1"
            ],
            "import_time": "2026-04-20T00:43:15.38090661Z",
            "modified_time": "2026-04-07T19:23:02Z",
            "sha256": "013b2c71633a40b8d425f998bb589074e403eea3069a0af42d70a041827475a3"
        }
    ]
}
References
Credits

Affected packages

npm / @velora-dex/sdk

Package

Name
@velora-dex/sdk
View open source insights on deps.dev
Purl
pkg:npm/%40velora-dex/sdk

Affected ranges

Affected versions

9.*
9.4.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@velora-dex/sdk/MAL-2026-2510.json"