MAL-2026-2523

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@telekom-wfa/auth-core/MAL-2026-2523.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2523
Published
2026-04-09T08:25:05Z
Modified
2026-04-10T17:36:05.508275Z
Summary
Malicious code in @telekom-wfa/auth-core (npm)
Details

Package is malware. Hardcoded Telegram credentials, data exfiltration, and preinstall script execution indicate malicious intent.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (9a2fe12e5542ae8cf1cf339c13c3480629ccfd6e2fb391427c4f1b17bbdc9f85)

The package @telekom-wfa/auth-core was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-10T17:21:50.426527066Z",
            "sha256": "9a2fe12e5542ae8cf1cf339c13c3480629ccfd6e2fb391427c4f1b17bbdc9f85",
            "source": "amazon-inspector",
            "modified_time": "2026-04-10T17:02:58Z",
            "versions": [
                "99.9.11"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @telekom-wfa/auth-core

Package

Name
@telekom-wfa/auth-core
View open source insights on deps.dev
Purl
pkg:npm/%40telekom-wfa/auth-core

Affected ranges

Affected versions

99.*
99.9.11

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@telekom-wfa/auth-core/MAL-2026-2523.json"