MAL-2024-3040

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/spring-projects/MAL-2024-3040.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2024-3040
Aliases
  • SNYK-JS-SPRINGPROJECTS-6044698
Published
2024-06-25T13:01:44Z
Modified
2024-10-24T01:01:57Z
Summary
Malicious code in spring-projects (npm)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "7ea4dc2b777119bfe1ec4ab102bd374d8f0dd3a59ff7b738a97591be78fa4517",
            "import_time": "2024-06-28T02:44:47.52483004Z",
            "versions": [
                "6.0.4",
                "6.0.2",
                "6.0.3"
            ],
            "id": "RLMA-2024-01775",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T13:01:44Z"
        },
        {
            "sha256": "d44b1f2bc385bd1501dc08678a19d331221b41a074f8321c77fb84ec9a467201",
            "import_time": "2024-10-24T00:58:21.982469258Z",
            "id": "RLUA-2024-07345",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T13:20:21Z"
        }
    ]
}
References
Credits

Affected packages

npm / spring-projects

Package

Affected ranges

Affected versions

6.*

6.0.2
6.0.3
6.0.4