{"id":"MAL-2026-2498","summary":"Malicious code in df-sandbox-test (npm)","details":"Multiple evidences indicate malicious behaviors: data exfiltration, sensitive file access, obfuscated code, and suspicious network connections.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (97761ee82976dcee2c3d8438258e8ace733bec2d2c7e1020035e9e390f9fa02f)\nThe package df-sandbox-test was found to contain malicious code.\n","modified":"2026-04-07T14:52:52.101861Z","published":"2026-04-06T09:18:00Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-04-07T14:24:50Z","import_time":"2026-04-07T14:39:07.563032925Z","ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"sha256":"97761ee82976dcee2c3d8438258e8ace733bec2d2c7e1020035e9e390f9fa02f","source":"amazon-inspector"}]},"references":[{"type":"REPORT","url":"https://app.safedep.io/community/malysis/01KNESB3A5J7Z9ZMWMZD56NBX5"}],"affected":[{"package":{"name":"df-sandbox-test","ecosystem":"npm","purl":"pkg:npm/df-sandbox-test"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/df-sandbox-test/MAL-2026-2498.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}