MAL-2026-40

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/spire.officejs-editors/MAL-2026-40.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-40
Published
2026-01-05T00:40:44Z
Modified
2026-01-08T09:34:55.158725Z
Summary
Malicious code in spire.officejs-editors (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a16e661181ec9b4834133423f88991671288814200d66aa148195cc9c06b5aff)

The package spire.officejs-editors was found to contain malicious code.

Source: ossf-package-analysis (23e1802d7b4c42af094b402bde9c0661dd70e4ed1133cd7233d70fa4bfb98e17)

The OpenSSF Package Analysis project identified 'spire.officejs-editors' @ 99.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-01-05T00:40:44Z",
            "versions": [
                "99.0.1"
            ],
            "sha256": "23e1802d7b4c42af094b402bde9c0661dd70e4ed1133cd7233d70fa4bfb98e17",
            "source": "ossf-package-analysis",
            "import_time": "2026-01-05T00:56:19.924438239Z"
        },
        {
            "modified_time": "2026-01-05T01:10:41Z",
            "versions": [
                "1.0.0"
            ],
            "sha256": "17f663bd751819985d992450d479ab46c9d52f68bf9f63d80f70cbd2fee414a7",
            "source": "ossf-package-analysis",
            "import_time": "2026-01-05T01:36:57.841694092Z"
        },
        {
            "modified_time": "2026-01-08T09:02:00Z",
            "versions": [
                "99.0.1",
                "1.0.0"
            ],
            "sha256": "a16e661181ec9b4834133423f88991671288814200d66aa148195cc9c06b5aff",
            "source": "amazon-inspector",
            "import_time": "2026-01-08T09:11:24.941393789Z"
        }
    ]
}
References
Credits

Affected packages

npm / spire.officejs-editors

Package

Name
spire.officejs-editors
View open source insights on deps.dev
Purl
pkg:npm/spire.officejs-editors

Affected ranges

Affected versions

1.*
1.0.0
99.*
99.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/spire.officejs-editors/MAL-2026-40.json"