{"id":"MAL-2026-11","summary":"Malicious code in cc-double-1 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f70cef7c9872833a60083bf6c209e3c0820db61d4350689db8b2480b58026874)\nThe package cc-double-1 was found to contain malicious code.\n","modified":"2026-03-19T12:40:52.019734Z","published":"2026-01-02T22:06:48Z","database_specific":{"malicious-packages-origins":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"modified_time":"2026-01-02T22:06:48Z","source":"amazon-inspector","import_time":"2026-01-02T22:07:13.03297033Z","sha256":"f70cef7c9872833a60083bf6c209e3c0820db61d4350689db8b2480b58026874"},{"versions":["99.99.99"],"id":"RLMA-2026-01140","modified_time":"2026-03-18T12:41:56Z","source":"reversing-labs","import_time":"2026-03-19T12:18:35.972019677Z","sha256":"01195e6110caeb65ba3321319f38ead6813596481303649814d19bb646b082ee"}]},"affected":[{"package":{"name":"cc-double-1","ecosystem":"npm","purl":"pkg:npm/cc-double-1"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["99.99.99"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cc-double-1/MAL-2026-11.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}