{"id":"MAL-2024-1145","summary":"Malicious code in odyssey-lint-staged (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (0b408f794010d1926bb9841d26fd28c91c97d8f11d71acea664c92ccb5a06a54)\nThe OpenSSF Package Analysis project identified 'odyssey-lint-staged' @ 9.9.5 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2024-06-28T02:53:16Z","published":"2024-03-24T14:46:39Z","database_specific":{"malicious-packages-origins":[{"import_time":"2024-03-24T15:04:50.805749271Z","modified_time":"2024-03-24T14:46:39Z","sha256":"0b408f794010d1926bb9841d26fd28c91c97d8f11d71acea664c92ccb5a06a54","source":"ossf-package-analysis","versions":["9.9.5"]},{"modified_time":"2024-06-25T12:53:49Z","sha256":"97be82a0b6996138462bbea2eb5753a6ecb5a6b30ca5caec87b5e95c626bbe50","source":"reversing-labs","versions":["9.9.5"],"id":"RLMA-2024-01489","import_time":"2024-06-28T02:44:13.48656029Z"}]},"affected":[{"package":{"name":"odyssey-lint-staged","ecosystem":"npm","purl":"pkg:npm/odyssey-lint-staged"},"versions":["9.9.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/odyssey-lint-staged/MAL-2024-1145.json"}}],"schema_version":"1.7.3","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}