{"id":"MAL-2026-1790","summary":"Malicious code in manifest-confusion-poc-audit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bdce3a4402dab0a3cd3ccff6522e439711936fb0c4077ea260dde4b8392cddc1)\nThe package manifest-confusion-poc-audit was found to contain malicious code.\n","modified":"2026-03-23T05:43:54.869764Z","published":"2026-03-18T12:58:40Z","database_specific":{"malicious-packages-origins":[{"versions":["999999999.999999999.999999999"],"source":"reversing-labs","id":"RLMA-2026-01426","sha256":"f14577d0e24ac0386f40d3c18ca8c242a177f0add4958472b1f1b8738fd92696","import_time":"2026-03-19T12:19:00.977040532Z","modified_time":"2026-03-18T12:58:40Z"},{"versions":["999999999.999999999.999999999"],"source":"amazon-inspector","sha256":"bdce3a4402dab0a3cd3ccff6522e439711936fb0c4077ea260dde4b8392cddc1","import_time":"2026-03-23T05:14:01.252492493Z","modified_time":"2026-03-23T05:11:41Z"}]},"affected":[{"package":{"name":"manifest-confusion-poc-audit","ecosystem":"npm","purl":"pkg:npm/manifest-confusion-poc-audit"},"versions":["999999999.999999999.999999999"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/manifest-confusion-poc-audit/MAL-2026-1790.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}