MAL-2026-3422

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rsflows-pexml/MAL-2026-3422.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3422
Published
2026-05-10T15:15:31Z
Modified
2026-05-12T07:57:52.591710Z
Summary
Malicious code in rsflows-pexml (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4ef5b11ec067e18cc3a024fee21e569e0f44cf180619e974cbb1dd8325e1b10c)

The package rsflows-pexml was found to contain malicious code.

Source: ossf-package-analysis (ca8cde633391c1292f4bc8a50e783760044b5bea6312639fb3470418619c1b9d)

The OpenSSF Package Analysis project identified 'rsflows-pexml' @ 99.9.25 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-05-11T00:52:26.816722037Z",
            "sha256": "144a8e247e6bb6c7b08119900b2d70af4ee7a594650d03adb2fbf731963e521d",
            "source": "ossf-package-analysis",
            "modified_time": "2026-05-10T15:15:31Z",
            "versions": [
                "99.9.9"
            ]
        },
        {
            "import_time": "2026-05-11T00:52:26.660792127Z",
            "sha256": "ca8cde633391c1292f4bc8a50e783760044b5bea6312639fb3470418619c1b9d",
            "source": "ossf-package-analysis",
            "modified_time": "2026-05-10T15:50:50Z",
            "versions": [
                "99.9.25"
            ]
        },
        {
            "import_time": "2026-05-12T07:28:56.38973164Z",
            "sha256": "4ef5b11ec067e18cc3a024fee21e569e0f44cf180619e974cbb1dd8325e1b10c",
            "source": "amazon-inspector",
            "modified_time": "2026-05-12T06:53:21Z",
            "versions": [
                "99.9.9",
                "99.9.25"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / rsflows-pexml

Package

Affected ranges

Affected versions

99.*
99.9.9
99.9.25

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rsflows-pexml/MAL-2026-3422.json"