MAL-2026-873

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@depro0x/despicable-me/MAL-2026-873.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-873
Published
2026-02-12T20:40:54Z
Modified
2026-03-23T04:55:33.755841Z
Summary
Malicious code in @depro0x/despicable-me (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (0e512041534d296b22312d733434bb54944a4e026f6ddeaa493240cccc429ee9)

The package @depro0x/despicable-me was found to contain malicious code.

Source: ossf-package-analysis (4615e7677b737a414d7c43332b795fe84cb5d272e491befba14d42456ae28cfc)

The OpenSSF Package Analysis project identified '@depro0x/despicable-me' @ 11.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "versions": [
                "8.0.0"
            ],
            "import_time": "2026-02-12T20:46:27.750833393Z",
            "modified_time": "2026-02-12T20:40:54Z",
            "sha256": "6462180066b4c25e184d616993e44ba94d6e6fdf065db3e0e6ce52a1015a0aa0"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "14.0.0"
            ],
            "import_time": "2026-02-12T21:13:09.941100803Z",
            "modified_time": "2026-02-12T21:04:06Z",
            "sha256": "408ee2d3c535747e02e11f32f8a20bafa12ddc1ac413c41dc80ed7375e926b02"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "9.0.0"
            ],
            "import_time": "2026-02-12T21:13:09.774236826Z",
            "modified_time": "2026-02-12T20:47:18Z",
            "sha256": "e5e59fdbcd5eae4cddc95424e34ba5de09ae15fd2d265fcf832a68c4c4495a4a"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "11.0.0"
            ],
            "import_time": "2026-02-12T21:45:29.334645302Z",
            "modified_time": "2026-02-12T21:37:57Z",
            "sha256": "4615e7677b737a414d7c43332b795fe84cb5d272e491befba14d42456ae28cfc"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "13.0.0"
            ],
            "import_time": "2026-02-12T21:45:29.187884531Z",
            "modified_time": "2026-02-12T21:29:31Z",
            "sha256": "9d4f645b4e971818c96437326820425423bc5c41700995b66b0a6d96d110f145"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "16.0.0"
            ],
            "import_time": "2026-02-12T21:45:29.076722365Z",
            "modified_time": "2026-02-12T21:21:01Z",
            "sha256": "cfd0bd7743a9548666d2cb6e0bbe7392bde2f52356f29403ba18b846c2f6c8d0"
        },
        {
            "source": "ossf-package-analysis",
            "versions": [
                "6.0.0"
            ],
            "import_time": "2026-02-12T22:45:32.411452612Z",
            "modified_time": "2026-02-12T22:19:52Z",
            "sha256": "3fc28a0966ecc924884cf1cd6a75caf42b173878d6934a7f4774e294fba62ccd"
        },
        {
            "source": "amazon-inspector",
            "versions": [
                "8.0.0",
                "14.0.0",
                "9.0.0",
                "11.0.0",
                "13.0.0",
                "16.0.0",
                "6.0.0"
            ],
            "import_time": "2026-02-23T04:19:45.059722132Z",
            "modified_time": "2026-02-23T03:51:30Z",
            "sha256": "0e512041534d296b22312d733434bb54944a4e026f6ddeaa493240cccc429ee9"
        }
    ]
}
References
Credits

Affected packages

npm / @depro0x/despicable-me

Package

Name
@depro0x/despicable-me
View open source insights on deps.dev
Purl
pkg:npm/%40depro0x/despicable-me

Affected ranges

Affected versions

6.*
6.0.0
8.*
8.0.0
9.*
9.0.0
11.*
11.0.0
13.*
13.0.0
14.*
14.0.0
16.*
16.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@depro0x/despicable-me/MAL-2026-873.json"