MAL-2026-3074

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axis-abc-portal-menu/MAL-2026-3074.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3074
Published
2026-04-25T09:45:52Z
Modified
2026-05-05T00:07:13.831831Z
Summary
Malicious code in axis-abc-portal-menu (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (84dbd03fbc7970d1f3fc987743f698a9ea6a0af44ea2b89d0f2c1cbaa397f933)

The package axis-abc-portal-menu was found to contain malicious code.

Source: ossf-package-analysis (e394d219d698bd133d0914b1fb257d0a422174497c777a31dab1e5fc55a1b47e)

The OpenSSF Package Analysis project identified 'axis-abc-portal-menu' @ 99.99.99 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-27T01:40:40.483613796Z",
            "sha256": "51849e0e7d00b162d43e21c661c2ab928d218219382a14b8c0235dc101439b09",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-25T09:45:52Z",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "import_time": "2026-04-30T22:23:12.375884952Z",
            "sha256": "84dbd03fbc7970d1f3fc987743f698a9ea6a0af44ea2b89d0f2c1cbaa397f933",
            "source": "amazon-inspector",
            "modified_time": "2026-04-30T21:59:18Z",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "import_time": "2026-05-04T03:13:21.951776617Z",
            "sha256": "e394d219d698bd133d0914b1fb257d0a422174497c777a31dab1e5fc55a1b47e",
            "source": "ossf-package-analysis",
            "modified_time": "2026-05-03T12:25:37Z",
            "versions": [
                "99.99.99"
            ]
        },
        {
            "import_time": "2026-05-04T23:49:27.560510171Z",
            "sha256": "1b92454a3753c68e1011df3bcf8f965b68941e933f0c00e2b75be438011446bc",
            "source": "ossf-package-analysis",
            "modified_time": "2026-05-04T13:30:44Z",
            "versions": [
                "100.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / axis-abc-portal-menu

Package

Name
axis-abc-portal-menu
View open source insights on deps.dev
Purl
pkg:npm/axis-abc-portal-menu

Affected ranges

Affected versions

1.*
1.0.0
99.*
99.99.99
100.*
100.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axis-abc-portal-menu/MAL-2026-3074.json"