MAL-2026-2928

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pa-marked-internal/MAL-2026-2928.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2928
Published
2026-04-19T18:50:52Z
Modified
2026-04-23T21:19:30.209388Z
Summary
Malicious code in pa-marked-internal (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (aa7ec58688a86a684649482df31ee2d5ded2b22d648049ab9a2d6ba93bb912b0)

The package pa-marked-internal was found to contain malicious code.

Source: ossf-package-analysis (1d618c2f983bf33eb7a449adf96ad491b51b23573e34f3ccdf8ed960147ed70e)

The OpenSSF Package Analysis project identified 'pa-marked-internal' @ 1.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-20T04:35:30.813622661Z",
            "sha256": "1d618c2f983bf33eb7a449adf96ad491b51b23573e34f3ccdf8ed960147ed70e",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-19T18:50:52Z",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "import_time": "2026-04-20T04:35:30.90845433Z",
            "sha256": "aac4ede7ac259c3abd6ce42f4c79498f8307ce22b67f5c4c5aa10f19142c570c",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-19T18:55:37Z",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "import_time": "2026-04-23T20:49:05.282925642Z",
            "sha256": "aa7ec58688a86a684649482df31ee2d5ded2b22d648049ab9a2d6ba93bb912b0",
            "source": "amazon-inspector",
            "modified_time": "2026-04-23T20:43:56Z",
            "versions": [
                "1.0.1",
                "1.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / pa-marked-internal

Package

Affected ranges

Affected versions

1.*
1.0.1
1.0.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pa-marked-internal/MAL-2026-2928.json"