{"id":"MAL-2024-2845","summary":"Malicious code in pattern.json (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n","modified":"2024-10-24T01:01:56Z","published":"2024-06-25T12:55:20Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2024-01558","import_time":"2024-06-28T02:44:21.936183208Z","modified_time":"2024-06-25T12:55:20Z","sha256":"21ee85d2f4d0f50b02e9dd6505948acdd76f211d52ac78880696b3e327f12f10","source":"reversing-labs","versions":["4.12.7"]},{"source":"reversing-labs","id":"RLUA-2024-07075","import_time":"2024-10-24T00:58:12.811959255Z","modified_time":"2024-10-16T13:10:40Z","sha256":"cb9b3025fa974a5b77412fe4ced06d8adeadf169594ed89a844b7600cc8290f9"}]},"references":[{"type":"ARTICLE","url":"https://www.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites"}],"affected":[{"package":{"name":"pattern.json","ecosystem":"npm","purl":"pkg:npm/pattern.json"},"versions":["4.12.7"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pattern.json/MAL-2024-2845.json"}}],"schema_version":"1.7.3","credits":[{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}