MAL-2024-1077

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@spectrocoin/sc-currencies/MAL-2024-1077.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2024-1077
Published
2024-03-08T06:21:43Z
Modified
2024-03-11T10:34:46Z
Summary
Malicious code in @spectrocoin/sc-currencies (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (e25c79935b85d9e21d6f39b9f9d5b8d7472c19cd2e49dd4239a6f7298e96502f)

The OpenSSF Package Analysis project identified '@spectrocoin/sc-currencies' @ 9.9.99 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-03-08T06:21:43Z",
            "import_time": "2024-03-11T10:34:30.090809536Z",
            "versions": [
                "9.9.9"
            ],
            "source": "ossf-package-analysis",
            "sha256": "537614613b01d474e908aa41f481754b741c65213d9ed488580f28402efb17cb"
        },
        {
            "modified_time": "2024-03-08T07:00:55Z",
            "import_time": "2024-03-11T10:34:30.230516267Z",
            "versions": [
                "9.9.99"
            ],
            "source": "ossf-package-analysis",
            "sha256": "e25c79935b85d9e21d6f39b9f9d5b8d7472c19cd2e49dd4239a6f7298e96502f"
        }
    ]
}
References
Credits

Affected packages

npm / @spectrocoin/sc-currencies

Package

Name
@spectrocoin/sc-currencies
View open source insights on deps.dev
Purl
pkg:npm/%40spectrocoin/sc-currencies

Affected ranges

Affected versions

9.*

9.9.9
9.9.99