Lucene search

K
osvGoogleOSV:MAL-2024-1617
HistoryJun 09, 2024 - 6:00 p.m.

Malicious code in test-pkg-blabla (npm)

2024-06-0918:00:33
Google
osv.dev
1
malicious
communication
package
npm

7.1 High

AI Score

Confidence

High


-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (3bfaca810c52dc5570fa40d75892333e31b5783eb2daa0f64c6db415c0e4ef79)

The OpenSSF Package Analysis project identified ‘test-pkg-blabla’ @ 1.0.11 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

7.1 High

AI Score

Confidence

High