MAL-2026-2734

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/buildkite-test-collector-mocha-example/MAL-2026-2734.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2734
Published
2026-04-16T09:47:30Z
Modified
2026-04-23T21:15:54.724719Z
Summary
Malicious code in buildkite-test-collector-mocha-example (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (37fbbae0cc3cfcba7b18566c1ab1f61417b1776206c3d0317956058c43ef61fa)

The package buildkite-test-collector-mocha-example was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-16T15:38:54.098049772Z",
            "versions": [
                "99.99.9"
            ],
            "source": "reversing-labs",
            "id": "RLMA-2026-01900",
            "modified_time": "2026-04-16T09:47:30Z",
            "sha256": "71e43ae286ee74c51f6ebca7ea9231aaf21ef9fbff6bba6888c7374346edc691"
        },
        {
            "import_time": "2026-04-23T20:49:09.512723548Z",
            "versions": [
                "99.99.9"
            ],
            "sha256": "37fbbae0cc3cfcba7b18566c1ab1f61417b1776206c3d0317956058c43ef61fa",
            "modified_time": "2026-04-23T20:43:56Z",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / buildkite-test-collector-mocha-example

Package

Name
buildkite-test-collector-mocha-example
View open source insights on deps.dev
Purl
pkg:npm/buildkite-test-collector-mocha-example

Affected ranges

Affected versions

99.*
99.99.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/buildkite-test-collector-mocha-example/MAL-2026-2734.json"