MAL-2026-2725

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/agent-framework-web/MAL-2026-2725.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2725
Published
2026-04-16T09:43:12Z
Modified
2026-04-23T21:12:43.258552Z
Summary
Malicious code in agent-framework-web (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fc8c54e8fb3b687786f6141ea8ea92fa6eeb60de018eb8543a325bac6eed1f67)

The package agent-framework-web was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-01881",
            "versions": [
                "9.9.9"
            ],
            "import_time": "2026-04-16T15:38:51.753677492Z",
            "modified_time": "2026-04-16T09:43:12Z",
            "sha256": "0be106850461b30ccab23bc2e3aca799d202f6729a9083da8332e8bf930d97e6"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "9.9.9"
            ],
            "import_time": "2026-04-23T20:49:07.670246635Z",
            "modified_time": "2026-04-23T20:43:56Z",
            "sha256": "fc8c54e8fb3b687786f6141ea8ea92fa6eeb60de018eb8543a325bac6eed1f67"
        }
    ]
}
References
Credits

Affected packages

npm / agent-framework-web

Package

Name
agent-framework-web
View open source insights on deps.dev
Purl
pkg:npm/agent-framework-web

Affected ranges

Affected versions

9.*
9.9.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/agent-framework-web/MAL-2026-2725.json"