{"id":"MAL-2023-1342","summary":"Malicious code in webpack-cli.legacy (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (22737261df7f74819a3f3f968e6516db5e37f6621827d6148b290f7650b9992f)\nThe OpenSSF Package Analysis project identified 'webpack-cli.legacy' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n- The package communicates with a domain associated with malicious activity.\n","aliases":["SNYK-JS-WEBPACKCLILEGACY-3336028"],"modified":"2024-06-28T03:14:43.729355Z","published":"2023-05-01T23:44:04Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"modified_time":"2023-05-01T23:44:04.442404944Z","import_time":"2023-08-10T06:15:30.720757513Z","source":"ossf-package-analysis","sha256":"22737261df7f74819a3f3f968e6516db5e37f6621827d6148b290f7650b9992f"},{"id":"RLMA-2024-02718","versions":["1.0.0"],"modified_time":"2024-06-25T13:21:42Z","import_time":"2024-06-28T02:46:37.689171445Z","source":"reversing-labs","sha256":"36a1cb0f22f58b250c2d77254ba2e5c49ff705178b4225a9df44d41640dc2144"}]},"references":[{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-WEBPACKCLILEGACY-3336028"}],"affected":[{"package":{"name":"webpack-cli.legacy","ecosystem":"npm","purl":"pkg:npm/webpack-cli.legacy"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webpack-cli.legacy/MAL-2023-1342.json"}}],"schema_version":"1.7.3","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}