MAL-2023-7942

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/twentynineteen/MAL-2023-7942.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2023-7942
Published
2023-08-29T09:17:23Z
Modified
2024-06-28T02:53:17Z
Summary
Malicious code in twentynineteen (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (41e718fa7d54fba600dedc033d1d1c93b282fdae82403869bf77c53363acf842)

The OpenSSF Package Analysis project identified 'twentynineteen' @ 2.5.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "41e718fa7d54fba600dedc033d1d1c93b282fdae82403869bf77c53363acf842",
            "import_time": "2023-08-29T09:34:30.099413982Z",
            "versions": [
                "2.5.1"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2023-08-29T09:17:23Z"
        },
        {
            "sha256": "29c4dfd6c0e1675b598f9c8a213260493dc4680345e178dbd0ac197cb4555a3f",
            "import_time": "2024-06-28T02:45:14.949761785Z",
            "versions": [
                "2.5.1",
                "1.0.2"
            ],
            "id": "RLMA-2024-02005",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T13:06:40Z"
        }
    ]
}
References
Credits

Affected packages

npm / twentynineteen

Package

Affected ranges

Affected versions

1.*

1.0.2

2.*

2.5.1