MAL-2026-9467

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/wprox-c217-extra4/MAL-2026-9467.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-9467
Aliases
  • GHSA-pxcx-6284-8mhj
Published
2026-07-07T12:10:46Z
Modified
2026-07-18T11:05:25.031511990Z
Summary
Malicious code in wprox-c217-extra4 (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

## Source: ghsa-malware (598125d7276ea48313cdbfc0c87ed8fefd7026734c8302d79d0e625d3ade2470)

Credit: OpenSSF (source)

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-07-09T09:14:57.649459959Z",
            "modified_time": "2026-07-07T12:10:46Z",
            "sha256": "b6ddb26b65755b3922cf7706e6fde393f04331eb7e5fab6b4fdd69199562e059",
            "versions": [
                "0.0.1"
            ],
            "id": "RLMA-2026-04118",
            "source": "reversing-labs"
        },
        {
            "import_time": "2026-07-18T10:46:31.159834814Z",
            "modified_time": "2026-07-18T01:58:51Z",
            "sha256": "598125d7276ea48313cdbfc0c87ed8fefd7026734c8302d79d0e625d3ade2470",
            "versions": [
                "0.0.1"
            ],
            "id": "GHSA-pxcx-6284-8mhj",
            "source": "ghsa-malware"
        }
    ]
}
References
Credits

Affected packages

RubyGems / wprox-c217-extra4

Package

Name
wprox-c217-extra4
Purl
pkg:gem/wprox-c217-extra4

Affected ranges

Affected versions

0.*
0.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/wprox-c217-extra4/MAL-2026-9467.json"