{"id":"MAL-2026-1879","summary":"Malicious code in yahoo-commerce (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e3725b1c28bf27cb9ae988e61fc0c7b790b588587cef59086e7d63460f2241a9)\nThe package yahoo-commerce was found to contain malicious code.\n","modified":"2026-03-23T05:47:22.691673Z","published":"2026-03-18T13:16:42Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2026-01662","import_time":"2026-03-19T12:19:16.738165936Z","modified_time":"2026-03-18T13:16:42Z","sha256":"1d9b1475309cbeddd6421c8d19e447f33607997ef2faf0c8d6f6fc6dd9ff4a75","source":"reversing-labs","versions":["99.99.99"]},{"versions":["99.99.99"],"import_time":"2026-03-23T05:14:26.935499369Z","modified_time":"2026-03-23T05:11:41Z","sha256":"e3725b1c28bf27cb9ae988e61fc0c7b790b588587cef59086e7d63460f2241a9","source":"amazon-inspector"}]},"affected":[{"package":{"name":"yahoo-commerce","ecosystem":"npm","purl":"pkg:npm/yahoo-commerce"},"versions":["99.99.99"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/yahoo-commerce/MAL-2026-1879.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}