{"id":"MAL-2026-1792","summary":"Malicious code in metro-evaluator (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a2e35441f182ca0b66905b74b51c0db61c1d641d7ecc920cdfef2ddedff38dda)\nThe package metro-evaluator was found to contain malicious code.\n","modified":"2026-03-23T05:43:56.666136Z","published":"2026-03-18T12:59:10Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"import_time":"2026-03-19T12:19:01.235386402Z","sha256":"09503f00109608ce5f14b06afc3f9ce052fae01d60bb44cf6519bfe12ead8537","source":"reversing-labs","id":"RLMA-2026-01429","modified_time":"2026-03-18T12:59:10Z"},{"versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"import_time":"2026-03-23T05:14:03.135559745Z","source":"amazon-inspector","sha256":"a2e35441f182ca0b66905b74b51c0db61c1d641d7ecc920cdfef2ddedff38dda","modified_time":"2026-03-23T05:11:41Z"}]},"affected":[{"package":{"name":"metro-evaluator","ecosystem":"npm","purl":"pkg:npm/metro-evaluator"},"versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/metro-evaluator/MAL-2026-1792.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}