MAL-2026-780

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ac-element-engagement/MAL-2026-780.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-780
Published
2026-02-06T02:07:02Z
Modified
2026-03-19T12:39:49.846020Z
Summary
Malicious code in ac-element-engagement (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (781104558212062e46f87c009a2a0af57fb00f707c878b53dfc5a7c241cce06b)

The package ac-element-engagement was found to contain malicious code.

Source: ossf-package-analysis (eef247e16d151ebee82664252e941779eb47a9459bac9c66753fff360c19536f)

The OpenSSF Package Analysis project identified 'ac-element-engagement' @ 3.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2026-02-06T02:07:02Z",
            "import_time": "2026-02-06T03:03:33.061328474Z",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "sha256": "781104558212062e46f87c009a2a0af57fb00f707c878b53dfc5a7c241cce06b"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "3.0.1"
            ],
            "import_time": "2026-03-13T11:14:25.080306803Z",
            "modified_time": "2026-03-13T11:11:14Z",
            "sha256": "eef247e16d151ebee82664252e941779eb47a9459bac9c66753fff360c19536f"
        },
        {
            "source": "reversing-labs",
            "id": "RLMA-2026-01090",
            "versions": [
                "99.9.9"
            ],
            "import_time": "2026-03-19T12:18:31.836057217Z",
            "modified_time": "2026-03-18T12:37:27Z",
            "sha256": "0d3fe15507b8eab989723ccc7c12bcffab4fe7171ae0276a9cf4052a703a946e"
        }
    ]
}
References
Credits

Affected packages

npm / ac-element-engagement

Package

Name
ac-element-engagement
View open source insights on deps.dev
Purl
pkg:npm/ac-element-engagement

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.1
99.*
99.9.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ac-element-engagement/MAL-2026-780.json"