MAL-2026-3049

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/classlink/MAL-2026-3049.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-3049
Published
2026-04-26T17:10:32Z
Modified
2026-04-26T18:33:13.319904Z
Summary
Malicious code in classlink (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (82421cd03a138ada09a2a108b340c2ab748bbf0774a84b4f11bce5a57469d830)

The OpenSSF Package Analysis project identified 'classlink' @ 2.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-04-26T17:18:09.419656964Z",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-26T17:10:32Z",
            "versions": [
                "2.0.1"
            ],
            "sha256": "82421cd03a138ada09a2a108b340c2ab748bbf0774a84b4f11bce5a57469d830"
        },
        {
            "import_time": "2026-04-26T17:47:15.669485271Z",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-26T17:20:37Z",
            "versions": [
                "2.0.0"
            ],
            "sha256": "debbaff3b3ee5fc5a533eb4cb9e524249a27fd8f620e62cdbad2c41496e4bd3a"
        },
        {
            "import_time": "2026-04-26T18:19:59.996495176Z",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-26T18:05:49Z",
            "versions": [
                "2.0.3"
            ],
            "sha256": "5148515e90fd48786beba5126f32886c22dfa95a98a5e7d2e8ff2cc7084d3728"
        },
        {
            "import_time": "2026-04-26T18:19:59.843692537Z",
            "source": "ossf-package-analysis",
            "modified_time": "2026-04-26T17:55:44Z",
            "versions": [
                "2.0.2"
            ],
            "sha256": "aeed628f4d299f7316e5298bae314385cc7e1a19ca4ede4f990ba4fb44e9f046"
        }
    ]
}
References
Credits

Affected packages

npm / classlink

Package

Affected ranges

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/classlink/MAL-2026-3049.json"