MAL-2026-7646

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/dwpdf1248851/MAL-2026-7646.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-7646
Aliases
  • GHSA-mh26-jxhf-hv6w
Published
2026-07-07T11:52:29Z
Modified
2026-07-18T11:04:16.678300245Z
Summary
Malicious code in dwpdf1248851 (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

## Source: ghsa-malware (a7e00a3a4669dc6eeb1c470ecbd0a05bf101cc6fdfae4e169afda2fdec5784a9)

Credit: OpenSSF (source)

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-07-09T09:12:00.43548496Z",
            "modified_time": "2026-07-07T11:52:29Z",
            "sha256": "3921add728da593eddd7e4227bba02bff87e46c4b6e930ad2fff3e4bc1ffdbc8",
            "versions": [
                "0.0.1"
            ],
            "id": "RLMA-2026-02297",
            "source": "reversing-labs"
        },
        {
            "import_time": "2026-07-18T10:46:30.909279327Z",
            "source": "ghsa-malware",
            "sha256": "a7e00a3a4669dc6eeb1c470ecbd0a05bf101cc6fdfae4e169afda2fdec5784a9",
            "versions": [
                "0.0.1"
            ],
            "id": "GHSA-mh26-jxhf-hv6w",
            "modified_time": "2026-07-18T01:57:05Z"
        }
    ]
}
References
Credits

Affected packages

RubyGems / dwpdf1248851

Package

Name
dwpdf1248851
Purl
pkg:gem/dwpdf1248851

Affected ranges

Affected versions

0.*
0.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/dwpdf1248851/MAL-2026-7646.json"