MAL-2026-5024

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@mlspace/model-registry/MAL-2026-5024.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5024
Published
2026-05-28T00:00:00Z
Modified
2026-05-29T00:02:05.147145484Z
Summary
Malicious code in @mlspace/model-registry (npm)
Details

Part of a dependency confusion attack campaign targeting the @cloudplatform-single-spa and @mlspace npm scopes. The attacker (npm user mr.4nd3r50n) published 139 scoped packages at the inflated version 99.99.99, which resolves ahead of any private registry version via npm's default version resolution, silently hijacking installs of internal packages.

This specific package carries no active postinstall payload and its description claims "BugBounty testing". However, it squats a legitimate internal package namespace at an inflated version as part of the broader campaign.

Database specific
{
    "malicious-packages-origins": null
}
References
Credits

Affected packages

npm / @mlspace/model-registry

Package

Name
@mlspace/model-registry
View open source insights on deps.dev
Purl
pkg:npm/%40mlspace%2Fmodel-registry

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@mlspace/model-registry/MAL-2026-5024.json"