{"id":"MAL-2026-2243","summary":"Malicious code in browserstack-electron-forge-include-package-plugin (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e23283b4b946444b885ae39acf12ae0ca55ddd864863df70b0fcf84f5c5c57b3)\nThe package browserstack-electron-forge-include-package-plugin was found to contain malicious code.\n\n## Source: ossf-package-analysis (2befe1c3a5a6d72c06550b27e9f9fefd9ea296b3ef1bd4d1d90581e86733e319)\nThe OpenSSF Package Analysis project identified 'browserstack-electron-forge-include-package-plugin' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-03-31T03:22:32.198306Z","published":"2026-03-26T20:45:39Z","database_specific":{"malicious-packages-origins":[{"sha256":"2befe1c3a5a6d72c06550b27e9f9fefd9ea296b3ef1bd4d1d90581e86733e319","source":"ossf-package-analysis","import_time":"2026-03-26T20:46:14.448388777Z","versions":["99.0.0"],"modified_time":"2026-03-26T20:45:39Z"},{"sha256":"e23283b4b946444b885ae39acf12ae0ca55ddd864863df70b0fcf84f5c5c57b3","source":"amazon-inspector","import_time":"2026-03-31T03:10:13.239038691Z","versions":["99.0.0"],"modified_time":"2026-03-31T02:07:58Z"}]},"affected":[{"package":{"name":"browserstack-electron-forge-include-package-plugin","ecosystem":"npm","purl":"pkg:npm/browserstack-electron-forge-include-package-plugin"},"versions":["99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/browserstack-electron-forge-include-package-plugin/MAL-2026-2243.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}