MAL-2026-2723

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/actions-label-commenter/MAL-2026-2723.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2723
Published
2026-04-16T09:42:56Z
Modified
2026-04-23T21:12:43.588743Z
Summary
Malicious code in actions-label-commenter (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d0834799a232c7e018eda35f3042f85750f8155d2ec47e2f935389be689671cf)

The package actions-label-commenter was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-04-16T09:42:56Z",
            "versions": [
                "0.0.1"
            ],
            "sha256": "463e25622f371f592f1ba01958dc793b744aada4ef48f37ded71e21b0ba91f99",
            "id": "RLMA-2026-01877",
            "source": "reversing-labs",
            "import_time": "2026-04-16T15:38:51.460770492Z"
        },
        {
            "modified_time": "2026-04-23T20:43:56Z",
            "versions": [
                "0.0.1"
            ],
            "sha256": "d0834799a232c7e018eda35f3042f85750f8155d2ec47e2f935389be689671cf",
            "source": "amazon-inspector",
            "import_time": "2026-04-23T20:49:00.345526011Z"
        }
    ]
}
References
Credits

Affected packages

npm / actions-label-commenter

Package

Name
actions-label-commenter
View open source insights on deps.dev
Purl
pkg:npm/actions-label-commenter

Affected ranges

Affected versions

0.*
0.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/actions-label-commenter/MAL-2026-2723.json"