-= Per source details. Do not edit below this line.=-
The package advertises itself as MapLibre GL bindings for Vue 3 and re-exports the upstream maplibre-gl API, but on import it unconditionally injects a
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-007784",
"import_time": "2026-06-29T11:17:08.86340683Z",
"modified_time": "2026-06-29T09:11:39Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "a46347c152553bd008255683dd927e5f25233224d3c6f1df6ae87533350b5815",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-008996",
"import_time": "2026-07-08T23:27:58.181459554Z",
"modified_time": "2026-07-08T23:03:35Z",
"sha256": "6e3b161473fd04c687b0de94bcbeca68901125281f8166e295c308da167d38e1",
"source": "amazon-inspector",
"versions": [
"5.24.2"
]
},
{
"id": "IN-MAL-2026-008972",
"import_time": "2026-07-08T23:27:56.661258742Z",
"modified_time": "2026-07-08T23:00:11Z",
"sha256": "e0554b41a629091df72afc1730687b9af748668acfdd00ff539101203c49b31d",
"source": "amazon-inspector",
"versions": [
"5.24.1"
]
},
{
"id": "IN-MAL-2026-009418",
"import_time": "2026-07-09T22:02:29.367679459Z",
"modified_time": "2026-07-09T21:53:05Z",
"sha256": "c97e73217b484cb7a1ab73c2633f695b16be42e84d7be80bd5c72ecb38982031",
"source": "amazon-inspector",
"versions": [
"5.24.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "src/license.ts",
"sha256": "d7174b570716bf6f79dce63b66c4cf0f450cd4ab840431db127b411771eb7d15",
"tlsh": "38f0a6a43ce5d92f603a26a3517ad588762026123412a09e7b8c5d761962fd52e01d6e"
},
{
"path": "src/index.ts",
"sha256": "0a7262584f2fb7704275a3f03be4403fec4dd180f23e23f6025221f7f688d613",
"tlsh": "cac08cc30247d00b30f896c9001bd0afa3b0005f3a21702323030b3c8093ca02a0128c"
}
],
"package_integrity": [
{
"filename": "maplibre-gl-vue3-1.0.0.tgz",
"hashes": {
"sha1": "e59faa2636b3d36b1959a4751950568be80fda34",
"sha512_sri": "sha512-RYuIC2iJyU5SfTkXespzK7QXbcPOe544DW+B6ndaZX5PnHzLDZ0qmteTG5+h1zNxmPeot8YOOVm3RgKf3PEqdA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/maplibre-gl-vue3/MAL-2026-6592.json"