MAL-2026-2759

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-auth-basic/MAL-2026-2759.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2759
Published
2026-04-16T09:56:04Z
Modified
2026-04-23T21:15:51.851018Z
Summary
Malicious code in express-auth-basic (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1e643f12d60a16d07664d45cf59400356a38f8bb5463f358e1e86e217b88fab5)

The package express-auth-basic was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-01943",
            "versions": [
                "1.2.3"
            ],
            "import_time": "2026-04-16T15:39:01.418077806Z",
            "modified_time": "2026-04-16T09:56:04Z",
            "sha256": "d9816bd322adc64858055f576e3d66a1018b9cf74cc389169d87154c5ed7c72b"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "1.2.3"
            ],
            "import_time": "2026-04-23T20:49:15.456986773Z",
            "modified_time": "2026-04-23T20:43:56Z",
            "sha256": "1e643f12d60a16d07664d45cf59400356a38f8bb5463f358e1e86e217b88fab5"
        }
    ]
}
References
Credits

Affected packages

npm / express-auth-basic

Package

Affected ranges

Affected versions

1.*
1.2.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-auth-basic/MAL-2026-2759.json"