MAL-2023-6

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/parallel-workers/MAL-2023-6.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2023-6
Aliases
  • SNYK-JS-PARALLELWORKERS-3358943
Published
2023-04-27T06:36:28Z
Modified
2024-06-28T03:27:27.159998Z
Summary
Malicious code in parallel-workers (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (abf4ac32d4bbbf2bca51efed2166f670c707230f7da2b87c1318cbe8ca9dade1)

The OpenSSF Package Analysis project identified 'parallel-workers' @ 99.99.101 (npm) as malicious.

It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "9c0174e309ee35f18e3e4ecc04144c7841778774a8c0c0cb0b021b36d33dfb20",
            "import_time": "2023-06-30T03:52:49.169017309Z",
            "versions": [
                "99.99.99"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "0001-01-01T00:00:00Z"
        },
        {
            "sha256": "abf4ac32d4bbbf2bca51efed2166f670c707230f7da2b87c1318cbe8ca9dade1",
            "import_time": "2023-06-30T03:52:49.461728523Z",
            "versions": [
                "99.99.101"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "0001-01-01T00:00:00Z"
        },
        {
            "sha256": "50f20e0797ba51c8bd6fdd76af531e4eb24b29707d68640f25fc9caec492e986",
            "import_time": "2024-06-28T02:44:21.46425693Z",
            "versions": [
                "99.99.100",
                "99.99.99",
                "99.99.98",
                "99.99.101",
                "99.99.104"
            ],
            "id": "RLMA-2024-01554",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T12:55:11Z"
        }
    ]
}
References
Credits

Affected packages

npm / parallel-workers

Package

Affected ranges

Affected versions

99.*

99.99.98
99.99.99
99.99.100
99.99.101
99.99.104