MAL-2026-46

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/github-badge-bot/MAL-2026-46.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-46
Aliases
  • GHSA-r39w-33gw-8p5g
Published
2025-12-21T16:31:49Z
Modified
2026-01-11T22:39:48.342097Z
Summary
Malicious code in github-badge-bot (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (8f427bc7bcd3bfb173311bffdab461e2c6fc5350dc9ab3f7dc5e9a4ef6d16728)

The package github-badge-bot was found to contain malicious code.

Source: ghsa-malware (f87cd6af8d38dd37db1b6aca4f637451fe3303fa73ed0705216e3711bc4d0167)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Source: ossf-package-analysis (c1e71c7448fda61062fad2e007aee9c6c5efc95a862221eb62c14c5cb734d6b4)

The OpenSSF Package Analysis project identified 'github-badge-bot' @ 1.11.7 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-01-05T03:54:26.360085028Z",
            "modified_time": "2026-01-05T03:15:20Z",
            "source": "ghsa-malware",
            "sha256": "f87cd6af8d38dd37db1b6aca4f637451fe3303fa73ed0705216e3711bc4d0167",
            "id": "GHSA-r39w-33gw-8p5g",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ]
        },
        {
            "import_time": "2026-01-08T09:11:32.951529168Z",
            "modified_time": "2026-01-08T09:02:00Z",
            "source": "amazon-inspector",
            "sha256": "8f427bc7bcd3bfb173311bffdab461e2c6fc5350dc9ab3f7dc5e9a4ef6d16728",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.643125554Z",
            "modified_time": "2025-12-21T19:36:25Z",
            "source": "ossf-package-analysis",
            "sha256": "c1e71c7448fda61062fad2e007aee9c6c5efc95a862221eb62c14c5cb734d6b4",
            "versions": [
                "1.11.7"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.591111634Z",
            "modified_time": "2025-12-21T18:16:57Z",
            "source": "ossf-package-analysis",
            "sha256": "cefb771b2b26452ed43cdd31ce3974a90ada3a91f4bbb7d41839ff8f01bd6568",
            "versions": [
                "1.8.1"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.50792422Z",
            "modified_time": "2025-12-21T18:02:15Z",
            "source": "ossf-package-analysis",
            "sha256": "df8c7947c5b1bd80905a379b14f8b8b5d667f30039b2d563f4c6253846345f31",
            "versions": [
                "1.7.6"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.894215111Z",
            "modified_time": "2025-12-21T18:36:09Z",
            "source": "ossf-package-analysis",
            "sha256": "1ed92f7f3df0c47f34048a6289018b3c93da81641e2a51bb877d228f3c574a7b",
            "versions": [
                "1.9.0"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.970454412Z",
            "modified_time": "2025-12-21T18:41:10Z",
            "source": "ossf-package-analysis",
            "sha256": "4e8207e1887c69789379634df8a885892151921afb345d354e3e09ebcb89cbef",
            "versions": [
                "1.9.2"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.670756971Z",
            "modified_time": "2025-12-21T18:21:55Z",
            "source": "ossf-package-analysis",
            "sha256": "e2edf74eb2cf1073453a80702acd9b1ad8feffc28fbdde84df527568b1ece3ab",
            "versions": [
                "1.8.5"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.492833468Z",
            "modified_time": "2025-12-21T19:29:54Z",
            "source": "ossf-package-analysis",
            "sha256": "edebcc47b012c07b7b298bae609a8c8e5c38217aa37f56e57afdc89057bc4d90",
            "versions": [
                "1.11.3"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.573123988Z",
            "modified_time": "2025-12-21T19:31:37Z",
            "source": "ossf-package-analysis",
            "sha256": "1748d16ed65c2191d73006451bcce1410ffead9f3112cf7b11677f0d3628afbd",
            "versions": [
                "1.11.4"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.877201271Z",
            "modified_time": "2025-12-22T10:52:47Z",
            "source": "ossf-package-analysis",
            "sha256": "2710aecd9adfbf3952689b13a22f685f62abfdc3d9115ec409dff1d3e596470c",
            "versions": [
                "1.15.0"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.439610214Z",
            "modified_time": "2025-12-21T17:46:16Z",
            "source": "ossf-package-analysis",
            "sha256": "5aee29ac783a29d0b43c943373d38efa73033269d375073de911f3e9334bab90",
            "versions": [
                "1.7.3"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.36569735Z",
            "modified_time": "2025-12-21T17:42:08Z",
            "source": "ossf-package-analysis",
            "sha256": "7d2d0d71bc4d0515f3267f52194a198a29cb8fda424b181dc487315d83e7be1e",
            "versions": [
                "1.7.2"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.225621746Z",
            "modified_time": "2025-12-21T17:02:16Z",
            "source": "ossf-package-analysis",
            "sha256": "b273012aea1cc15eca4a4df90626fabed96d6013316a45c9dd9a4cd560aa2692",
            "versions": [
                "1.6.6"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.345298941Z",
            "modified_time": "2025-12-21T19:22:10Z",
            "source": "ossf-package-analysis",
            "sha256": "b4e52b5b5e7183af177f70b16bcdeaea40f2e64c1602619393de90d1338f8f72",
            "versions": [
                "1.11.2"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.798908667Z",
            "modified_time": "2025-12-22T10:47:27Z",
            "source": "ossf-package-analysis",
            "sha256": "e85fe6d79727da3a3c48e3d9aceda44db72238c46b48849e2ab7caf0045c7ac8",
            "versions": [
                "1.14.1"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.12179858Z",
            "modified_time": "2025-12-21T18:57:35Z",
            "source": "ossf-package-analysis",
            "sha256": "5a808226682b51460541af34bb3cfb91f2548782c2d058011c7200e82641d6c1",
            "versions": [
                "1.9.5"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.296319232Z",
            "modified_time": "2025-12-21T17:31:31Z",
            "source": "ossf-package-analysis",
            "sha256": "71240ebcb9828454340b08258268ed94ce7731c0a02682e0674feca3d1a69185",
            "versions": [
                "1.7.1"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.195605909Z",
            "modified_time": "2025-12-21T19:06:39Z",
            "source": "ossf-package-analysis",
            "sha256": "9156a899ca194cc826de766360057a6082ac80c0a8bd4ffdb0736c53a05900e1",
            "versions": [
                "1.10.0"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.81508867Z",
            "modified_time": "2025-12-21T18:31:40Z",
            "source": "ossf-package-analysis",
            "sha256": "c2651c5443ce04227f3a7c18e620258da12d28e80d77ff331a66455a7d7cd612",
            "versions": [
                "1.8.9"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.049496799Z",
            "modified_time": "2025-12-21T18:48:06Z",
            "source": "ossf-package-analysis",
            "sha256": "f21f6ce79b48d700e9fa73cbac7da1d7e75a6c8e0a559e74f4ff2e1020a943ab",
            "versions": [
                "1.9.4"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.744139571Z",
            "modified_time": "2025-12-21T18:28:02Z",
            "source": "ossf-package-analysis",
            "sha256": "ab6c74bf1d662901c091e88dad8693fb3612ec7a593cb063718f260307c432c0",
            "versions": [
                "1.8.7"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.41853025Z",
            "modified_time": "2025-12-21T19:27:39Z",
            "source": "ossf-package-analysis",
            "sha256": "2902fdc26601366c64df2a575bbad3c2d7772ad2b7100a861acecde2a4b08519",
            "versions": [
                "1.10.4"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:12.262884183Z",
            "modified_time": "2025-12-21T19:11:47Z",
            "source": "ossf-package-analysis",
            "sha256": "4ce849de3f475613519d935ebcec572904adb3cec9408846b4b59c8e7d84bf68",
            "versions": [
                "1.10.3"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.086944122Z",
            "modified_time": "2025-12-21T16:31:49Z",
            "source": "ossf-package-analysis",
            "sha256": "909d471ccef4d19b5d7196f52e7ee8e0d57acda765e40e28b392b82334d18391",
            "versions": [
                "1.6.3"
            ]
        },
        {
            "import_time": "2026-01-11T22:07:11.14921254Z",
            "modified_time": "2025-12-21T16:42:12Z",
            "source": "ossf-package-analysis",
            "sha256": "977332050e5500e60fe1591b2f32d5f5860349a1ed189483f9d82756dca12d28",
            "versions": [
                "1.6.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / github-badge-bot

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.6.3
1.6.4
1.6.6
1.7.1
1.7.2
1.7.3
1.7.6
1.8.1
1.8.5
1.8.7
1.8.9
1.9.0
1.9.2
1.9.4
1.9.5
1.10.0
1.10.3
1.10.4
1.11.2
1.11.3
1.11.4
1.11.7
1.14.1
1.15.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/github-badge-bot/MAL-2026-46.json"
cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]