MAL-2026-717

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/partnerss/MAL-2026-717.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-717
Published
2026-02-04T05:25:27Z
Modified
2026-02-06T03:23:51.364458Z
Summary
Malicious code in partnerss (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c370b0dbfdf4006f77ab698296da5eef2bb1a5ca43e91b932711518a3a0b8c5c)

The package partnerss was found to contain malicious code.

Source: ossf-package-analysis (8760f774e513cf8d18beaa321298ecd8c1a0eb17031f919b106c5c8bf45eeb41)

The OpenSSF Package Analysis project identified 'partnerss' @ 99.9.9 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "versions": [
                "99.9.9"
            ],
            "import_time": "2026-02-04T05:27:30.373351521Z",
            "modified_time": "2026-02-04T05:25:27Z",
            "sha256": "8760f774e513cf8d18beaa321298ecd8c1a0eb17031f919b106c5c8bf45eeb41"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "99.9.9"
            ],
            "import_time": "2026-02-06T03:03:32.735599863Z",
            "modified_time": "2026-02-06T02:07:02Z",
            "sha256": "c370b0dbfdf4006f77ab698296da5eef2bb1a5ca43e91b932711518a3a0b8c5c"
        }
    ]
}
References
Credits

Affected packages

npm / partnerss

Package

Affected ranges

Affected versions

99.*
99.9.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/partnerss/MAL-2026-717.json"