{"id":"MAL-2024-2","summary":"Malicious code in @cartus-core/cartus-common-ui (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (00ecedfab923e26d9afa1c15157b18d4f9662f062ffec7f4ce93ece0426eeeda)\nThe OpenSSF Package Analysis project identified '@cartus-core/cartus-common-ui' @ 11230000951.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2024-01-01T22:33:56Z","published":"2024-01-01T12:33:38Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2024-01-01T12:33:38Z","sha256":"e1cb0428ec77f27833f104360225710f2669706df0702c7779e3cf3f1b4946d6","import_time":"2024-01-01T12:40:45.688977557Z","versions":["200000001.0.0"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T12:47:56Z","sha256":"664b0901400ee7c7d3f40110ce2925f5b513ac75de888ee2d86f4c25a4354216","import_time":"2024-01-01T13:05:18.584352665Z","versions":["200000051.0.0"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T19:03:34Z","sha256":"642a26bc2539e5716fd7cd404408efe760e83b09c9ccb1b487c3e2831395edd8","import_time":"2024-01-01T19:04:49.956377949Z","versions":["230000951.0.0"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T18:37:18Z","sha256":"fb07fdb9bd3d95181ea1d455158c7e136d17dfaa4ca9164facebf0172a704760","import_time":"2024-01-01T19:04:49.749197782Z","versions":["230000051.0.0"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T19:30:03Z","sha256":"00ecedfab923e26d9afa1c15157b18d4f9662f062ffec7f4ce93ece0426eeeda","import_time":"2024-01-01T19:33:40.37183478Z","versions":["11230000951.0.1"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T19:31:58Z","sha256":"d52531303a037510d34ec70b702e6614a8b11a8804f488315ef46c3e3b2a7ffa","import_time":"2024-01-01T19:33:40.426289368Z","versions":["11230000951.0.0"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T21:38:56Z","sha256":"80539c4f71f44880d4451abb7d4680b70b2026ba5a5c8a2edcc4386c192a82a9","import_time":"2024-01-01T22:04:55.13449038Z","versions":["11230000951.0.7"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T20:47:17Z","sha256":"08f603e0b5cc16b8586f4f231aa2b8194beefed9e3ad5e7a2240ac0b0d823bd9","import_time":"2024-01-01T22:33:40.10017918Z","versions":["11230000951.0.4"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T20:40:31Z","sha256":"2c044429d884da1d1ce4092e67062df0e85ebfc03b014b312907cbac4890635e","import_time":"2024-01-01T22:33:39.95912093Z","versions":["11230000951.0.3"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T21:15:45Z","sha256":"a4730652997024ebd6ac5facfa4fe30f55d7fd427f749ca4fccfc559b57f164f","import_time":"2024-01-01T22:33:40.333767826Z","versions":["11230000951.0.5"],"source":"ossf-package-analysis"},{"modified_time":"2024-01-01T20:00:39Z","sha256":"ef137d971261f9aade7b489f2ca1c5b44140e773fc7ab21c747c2061e15eb253","import_time":"2024-01-01T22:33:39.772167131Z","versions":["11230000951.0.2"],"source":"ossf-package-analysis"}]},"affected":[{"package":{"name":"@cartus-core/cartus-common-ui","ecosystem":"npm","purl":"pkg:npm/%40cartus-core/cartus-common-ui"},"versions":["200000001.0.0","200000051.0.0","230000951.0.0","230000051.0.0","11230000951.0.1","11230000951.0.0","11230000951.0.7","11230000951.0.4","11230000951.0.3","11230000951.0.5","11230000951.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cartus-core/cartus-common-ui/MAL-2024-2.json"}}],"schema_version":"1.7.3","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}