MAL-2026-985

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/conduit-utils/MAL-2026-985.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-985
Published
2026-02-22T20:45:43Z
Modified
2026-02-23T03:40:15.799490Z
Summary
Malicious code in conduit-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (9f633d16f7a0d621de3ff6221f99ffbc77f942c409d0d2adfbe58307211688bf)

The OpenSSF Package Analysis project identified 'conduit-utils' @ 2.95.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "9f633d16f7a0d621de3ff6221f99ffbc77f942c409d0d2adfbe58307211688bf",
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-22T20:45:43Z",
            "import_time": "2026-02-23T03:07:53.285396759Z",
            "versions": [
                "2.95.0"
            ]
        },
        {
            "sha256": "fac3bb8f07f1c325e1044ce89971b90f9253dcb11b29e80fa2c50f1a1fbc885f",
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-22T20:55:43Z",
            "import_time": "2026-02-23T03:07:53.380645667Z",
            "versions": [
                "3.99.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / conduit-utils

Package

Affected ranges

Affected versions

2.*
2.95.0
3.*
3.99.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/conduit-utils/MAL-2026-985.json"