MAL-2026-848

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npm_cimetadata/MAL-2026-848.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-848
Published
2026-02-11T03:35:51Z
Modified
2026-02-23T04:34:03.661753Z
Summary
Malicious code in npm_cimetadata (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d1d7a7d39465b33d104fa6608118d45f3077d7a603292dd367135788a47e182d)

The package npm_cimetadata was found to contain malicious code.

Source: ossf-package-analysis (f7970f24b4e05cac8e0692834347b475d4ab966239b6ad39964ac45802ba49cb)

The OpenSSF Package Analysis project identified 'npm_cimetadata' @ 0.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-02-11T04:20:21.822427393Z",
            "sha256": "f7970f24b4e05cac8e0692834347b475d4ab966239b6ad39964ac45802ba49cb",
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-11T03:35:51Z",
            "versions": [
                "0.0.1"
            ]
        },
        {
            "import_time": "2026-02-11T08:19:24.108515989Z",
            "sha256": "15417f1edc00e00a75d1bd4508447dcb0f65c0e97d819237dc97d1143e975fe2",
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-11T08:15:50Z",
            "versions": [
                "0.0.2"
            ]
        },
        {
            "import_time": "2026-02-23T04:19:44.924951901Z",
            "sha256": "d1d7a7d39465b33d104fa6608118d45f3077d7a603292dd367135788a47e182d",
            "source": "amazon-inspector",
            "modified_time": "2026-02-23T03:51:30Z",
            "versions": [
                "0.0.1",
                "0.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / npm_cimetadata

Package

Affected ranges

Affected versions

0.*
0.0.1
0.0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npm_cimetadata/MAL-2026-848.json"