MAL-2024-11922

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/blz-internal-pkg_update/MAL-2024-11922.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2024-11922
Published
2024-12-19T11:50:49Z
Modified
2024-12-20T17:05:51Z
Summary
Malicious code in blz-internal-pkg_update (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (8c0576719ed89c86b80e8064de18e089618752aa208fa88dfc410ad73e84bf8e)

The OpenSSF Package Analysis project identified 'blz-internal-pkg_update' @ 7.7.11 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "8c0576719ed89c86b80e8064de18e089618752aa208fa88dfc410ad73e84bf8e",
            "import_time": "2024-12-19T12:08:58.896188961Z",
            "versions": [
                "7.7.11"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-19T11:55:53Z"
        },
        {
            "sha256": "932569e3f96886f9731675340f18ca15953074cb69922a6e77ef256b28b5363b",
            "import_time": "2024-12-19T12:08:58.806459796Z",
            "versions": [
                "7.7.9"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-19T11:50:49Z"
        },
        {
            "sha256": "22b7ba0d1c3b8e5b5dd1164d61508d7d0bf9932f8fd52521ac672c50cb822bdd",
            "import_time": "2024-12-20T16:37:49.789561661Z",
            "versions": [
                "7.7.14"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-20T16:31:03Z"
        },
        {
            "sha256": "a345201b8a7d112f2f876959b1a809c83236a7ab6d2f7136af1ab8362650a81c",
            "import_time": "2024-12-20T17:05:26.315186642Z",
            "versions": [
                "7.7.15"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-20T16:38:11Z"
        },
        {
            "sha256": "b5569612611d419e23a32156cb4d1119182a1e298dfd25a70741bdd62c83573e",
            "import_time": "2024-12-20T17:05:26.387017047Z",
            "versions": [
                "7.7.16"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2024-12-20T16:40:54Z"
        }
    ]
}
References
Credits

Affected packages

npm / blz-internal-pkg_update

Package

Name
blz-internal-pkg_update
View open source insights on deps.dev
Purl
pkg:npm/blz-internal-pkg_update

Affected ranges

Affected versions

7.*

7.7.9
7.7.11
7.7.14
7.7.15
7.7.16