MAL-2026-3336

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@channel_bot/xa0/MAL-2026-3336.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3336
Published
2026-05-04T13:51:12Z
Modified
2026-05-12T07:52:31.424340Z
Summary
Malicious code in @channel_bot/xa0 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (af511b868a0f1a7152f2b73076b3741da38a5ec9f8b2652af8384ca1890d9372)

The package @channel_bot/xa0 was found to contain malicious code.

Source: ossf-package-analysis (194976a861d5f77b7bfe921881d36c08ff7ced497269c62b1e55cfa0d63b7dca)

The OpenSSF Package Analysis project identified '@channel_bot/xa0' @ 9.9.99 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-05-04T14:07:24Z",
            "versions": [
                "9.9.99"
            ],
            "sha256": "194976a861d5f77b7bfe921881d36c08ff7ced497269c62b1e55cfa0d63b7dca",
            "source": "ossf-package-analysis",
            "import_time": "2026-05-04T23:49:28.408737252Z"
        },
        {
            "modified_time": "2026-05-04T13:51:12Z",
            "versions": [
                "9.9.9"
            ],
            "sha256": "f16bcb035c0de9f30a80b06e1163ec141bffb52870ad6dfff1bab028a3a32523",
            "source": "ossf-package-analysis",
            "import_time": "2026-05-04T23:49:28.278450628Z"
        },
        {
            "modified_time": "2026-05-12T06:53:21Z",
            "versions": [
                "9.9.99",
                "9.9.9"
            ],
            "sha256": "af511b868a0f1a7152f2b73076b3741da38a5ec9f8b2652af8384ca1890d9372",
            "source": "amazon-inspector",
            "import_time": "2026-05-12T07:28:52.590120832Z"
        }
    ]
}
References
Credits

Affected packages

npm / @channel_bot/xa0

Package

Name
@channel_bot/xa0
View open source insights on deps.dev
Purl
pkg:npm/%40channel_bot/xa0

Affected ranges

Affected versions

9.*
9.9.9
9.9.99

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@channel_bot/xa0/MAL-2026-3336.json"