MAL-2026-3338

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ms.analytics-web/MAL-2026-3338.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3338
Published
2026-05-04T19:06:03Z
Modified
2026-05-12T07:58:47.446408Z
Summary
Malicious code in ms.analytics-web (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f8603a11b43db05d179ab55b635a517ed40832c05fc4365a1ba69d2ec1eb5092)

The package ms.analytics-web was found to contain malicious code.

Source: ossf-package-analysis (35249931468fd68291141567ae436b4220f12fa0498d330bfc75ee82c772c1e7)

The OpenSSF Package Analysis project identified 'ms.analytics-web' @ 99.9.13 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "versions": [
                "99.9.13"
            ],
            "import_time": "2026-05-04T23:49:28.583722078Z",
            "modified_time": "2026-05-04T19:06:03Z",
            "sha256": "35249931468fd68291141567ae436b4220f12fa0498d330bfc75ee82c772c1e7"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "99.9.13"
            ],
            "import_time": "2026-05-12T07:28:58.883837209Z",
            "modified_time": "2026-05-12T06:53:21Z",
            "sha256": "f8603a11b43db05d179ab55b635a517ed40832c05fc4365a1ba69d2ec1eb5092"
        }
    ]
}
References
Credits

Affected packages

npm / ms.analytics-web

Package

Affected ranges

Affected versions

99.*
99.9.13

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ms.analytics-web/MAL-2026-3338.json"