MAL-2026-2822

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ing-web-v5/MAL-2026-2822.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2822
Published
2026-04-17T02:00:34Z
Modified
2026-04-17T03:17:57.044012Z
Summary
Malicious code in ing-web-v5 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6d0082d12c6909a9fcab28a2f2ad51cabf24e383f813999f6ad399ffcce08690)

The OpenSSF Package Analysis project identified 'ing-web-v5' @ 99.9.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-17T02:00:34Z",
            "sha256": "6d0082d12c6909a9fcab28a2f2ad51cabf24e383f813999f6ad399ffcce08690",
            "versions": [
                "99.9.1"
            ],
            "import_time": "2026-04-17T03:10:21.504695963Z"
        }
    ]
}
References
Credits

Affected packages

npm / ing-web-v5

Package

Affected ranges

Affected versions

99.*
99.9.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ing-web-v5/MAL-2026-2822.json"