MAL-2026-2744

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chain-metrica/MAL-2026-2744.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2744
Published
2026-04-16T09:49:16Z
Modified
2026-04-23T21:15:18.157717Z
Summary
Malicious code in chain-metrica (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fb624dbdf0ad26818c6d6685e22838c8bbb23d223376ba009f53500ca469ad86)

The package chain-metrica was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-04-16T09:49:16Z",
            "versions": [
                "2.4.5"
            ],
            "sha256": "c2ff52278c930c391f6ffa31d8733a5002bbbcdeda1e98aeaf7cfc7e2e2b41ac",
            "id": "RLMA-2026-01921",
            "source": "reversing-labs",
            "import_time": "2026-04-16T15:38:57.468515884Z"
        },
        {
            "modified_time": "2026-04-23T20:43:56Z",
            "versions": [
                "2.4.5"
            ],
            "sha256": "fb624dbdf0ad26818c6d6685e22838c8bbb23d223376ba009f53500ca469ad86",
            "source": "amazon-inspector",
            "import_time": "2026-04-23T20:48:58.836846676Z"
        }
    ]
}
References
Credits

Affected packages

npm / chain-metrica

Package

Affected ranges

Affected versions

2.*
2.4.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chain-metrica/MAL-2026-2744.json"