MAL-2024-9443

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sn-flow-client/MAL-2024-9443.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2024-9443
Published
2024-10-21T14:56:36Z
Modified
2024-10-21T14:56:36Z
Summary
Malicious code in sn-flow-client (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (40af2ecf250ffc74b1566c2e1b013c1fb2f8e1917dc5878511d1dbaf791c0c48)

The OpenSSF Package Analysis project identified 'sn-flow-client' @ 10.10.10 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-10-21T14:56:36Z",
            "import_time": "2024-10-21T15:05:44.825313176Z",
            "versions": [
                "10.10.10"
            ],
            "source": "ossf-package-analysis",
            "sha256": "40af2ecf250ffc74b1566c2e1b013c1fb2f8e1917dc5878511d1dbaf791c0c48"
        }
    ]
}
References
Credits

Affected packages

npm / sn-flow-client

Package

Affected ranges

Affected versions

10.*

10.10.10