MAL-2026-2801

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sfx-data/MAL-2026-2801.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2801
Published
2026-04-16T10:17:01Z
Modified
2026-04-23T21:17:46.741146Z
Summary
Malicious code in sfx-data (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d3fe291f014f24a669e43d0092e768f822241c223899812aeeb652ade2dcc63f)

The package sfx-data was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-04-16T10:17:01Z",
            "versions": [
                "2.1.0",
                "2.1.1",
                "99.0.0"
            ],
            "sha256": "545440223f73c3799538b3733680f9b3031bd6fb747dc967a91a9676c5ceef1e",
            "id": "RLMA-2026-02040",
            "source": "reversing-labs",
            "import_time": "2026-04-16T15:39:17.303140837Z"
        },
        {
            "modified_time": "2026-04-23T20:43:56Z",
            "versions": [
                "2.1.0",
                "2.1.1",
                "99.0.0"
            ],
            "sha256": "d3fe291f014f24a669e43d0092e768f822241c223899812aeeb652ade2dcc63f",
            "source": "amazon-inspector",
            "import_time": "2026-04-23T20:49:08.297736595Z"
        }
    ]
}
References
Credits

Affected packages

npm / sfx-data

Package

Affected ranges

Affected versions

2.*
2.1.0
2.1.1
99.*
99.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sfx-data/MAL-2026-2801.json"