{"id":"MAL-2026-1998","summary":"Malicious code in delphoi (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (72f68bb459a4772a75900ddec7e0a918b514f2211a2303aa80ef82252078e3b6)\nThe package delphoi was found to contain malicious code.\n\n## Source: ossf-package-analysis (c15c8182b6e392861478887a08b04eb8fecc38b70000313dfaf1cad8ac8bc831)\nThe OpenSSF Package Analysis project identified 'delphoi' @ 1.8.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-03-23T05:41:53.824785Z","published":"2026-03-20T11:44:11Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-03-20T12:16:42.544701958Z","versions":["1.8.2"],"source":"ossf-package-analysis","modified_time":"2026-03-20T11:44:11Z","sha256":"c15c8182b6e392861478887a08b04eb8fecc38b70000313dfaf1cad8ac8bc831"},{"import_time":"2026-03-23T05:14:24.913189863Z","versions":["1.8.2"],"source":"amazon-inspector","modified_time":"2026-03-23T05:11:41Z","sha256":"72f68bb459a4772a75900ddec7e0a918b514f2211a2303aa80ef82252078e3b6"}]},"affected":[{"package":{"name":"delphoi","ecosystem":"npm","purl":"pkg:npm/delphoi"},"versions":["1.8.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/delphoi/MAL-2026-1998.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}