MAL-2026-3430

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cplace-bmw-emt-mvp/MAL-2026-3430.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3430
Published
2026-05-11T17:58:02Z
Modified
2026-05-12T07:56:27.956585Z
Summary
Malicious code in cplace-bmw-emt-mvp (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (2b6d2d57176a41f11e925988396ad8549efc86508c1cc13a7130871f48c15b33)

The package cplace-bmw-emt-mvp was found to contain malicious code.

Source: ossf-package-analysis (a5df536f40d00940affdae35145eefe56cf78dc9302c4b2853776a4ae630182b)

The OpenSSF Package Analysis project identified 'cplace-bmw-emt-mvp' @ 2.0.4 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-05-11T18:44:01.71579989Z",
            "sha256": "a5df536f40d00940affdae35145eefe56cf78dc9302c4b2853776a4ae630182b",
            "source": "ossf-package-analysis",
            "modified_time": "2026-05-11T17:58:02Z",
            "versions": [
                "2.0.4"
            ]
        },
        {
            "import_time": "2026-05-12T07:28:53.094050364Z",
            "sha256": "2b6d2d57176a41f11e925988396ad8549efc86508c1cc13a7130871f48c15b33",
            "source": "amazon-inspector",
            "modified_time": "2026-05-12T06:53:21Z",
            "versions": [
                "2.0.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / cplace-bmw-emt-mvp

Package

Affected ranges

Affected versions

2.*
2.0.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cplace-bmw-emt-mvp/MAL-2026-3430.json"