MAL-2026-3128

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wm-plugin-teach-me-widget/MAL-2026-3128.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3128
Published
2026-04-28T10:21:02Z
Modified
2026-04-30T23:06:56.685363Z
Summary
Malicious code in wm-plugin-teach-me-widget (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a8892d058e7f10e304a86eea230ef7fa8fbf9a76da1d09b60f5498305690d4bc)

The package wm-plugin-teach-me-widget was found to contain malicious code.

Source: ossf-package-analysis (ebd46f9bf707420f68f24a52ca7bb9e517929d8e545802374dcb09697c8df410)

The OpenSSF Package Analysis project identified 'wm-plugin-teach-me-widget' @ 21.0.31 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-04-28T10:21:02Z",
            "import_time": "2026-04-28T11:13:50.147069477Z",
            "source": "ossf-package-analysis",
            "sha256": "ebd46f9bf707420f68f24a52ca7bb9e517929d8e545802374dcb09697c8df410",
            "versions": [
                "21.0.31"
            ]
        },
        {
            "modified_time": "2026-04-30T21:59:18Z",
            "import_time": "2026-04-30T22:23:10.873947487Z",
            "source": "amazon-inspector",
            "sha256": "a8892d058e7f10e304a86eea230ef7fa8fbf9a76da1d09b60f5498305690d4bc",
            "versions": [
                "21.0.31"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / wm-plugin-teach-me-widget

Package

Name
wm-plugin-teach-me-widget
View open source insights on deps.dev
Purl
pkg:npm/wm-plugin-teach-me-widget

Affected ranges

Affected versions

21.*
21.0.31

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wm-plugin-teach-me-widget/MAL-2026-3128.json"