{"id":"MAL-2026-2235","summary":"Malicious code in srcsrctest (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a44b46855732b5a5522c0a1ea3ef88d5977daad1bfa5c39b42e0324e52fcf6f8)\nThe package srcsrctest was found to contain malicious code.\n\n## Source: ossf-package-analysis (1aa147cd1bafdb2bf26b1c157edac9d3765ce544456e7f4e0fde95cd269af777)\nThe OpenSSF Package Analysis project identified 'srcsrctest' @ 1.0.6 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-03-31T03:24:52.090869Z","published":"2026-03-26T12:05:48Z","database_specific":{"malicious-packages-origins":[{"sha256":"1aa147cd1bafdb2bf26b1c157edac9d3765ce544456e7f4e0fde95cd269af777","source":"ossf-package-analysis","versions":["1.0.6"],"modified_time":"2026-03-26T12:15:48Z","import_time":"2026-03-26T12:25:46.32136861Z"},{"sha256":"9049c460c15f43120e5e8bb1207b5a642536124c66ff3dc7863e679e9d46b26e","source":"ossf-package-analysis","versions":["1.0.3"],"modified_time":"2026-03-26T12:05:48Z","import_time":"2026-03-26T12:25:46.220899442Z"},{"sha256":"a44b46855732b5a5522c0a1ea3ef88d5977daad1bfa5c39b42e0324e52fcf6f8","source":"amazon-inspector","versions":["1.0.6","1.0.3"],"modified_time":"2026-03-31T02:07:58Z","import_time":"2026-03-31T03:10:11.122342903Z"}]},"affected":[{"package":{"name":"srcsrctest","ecosystem":"npm","purl":"pkg:npm/srcsrctest"},"versions":["1.0.6","1.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/srcsrctest/MAL-2026-2235.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}