{"id":"MAL-2026-2710","summary":"Malicious code in @evoja-web/create-react-project (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (edb63f2bfa081652aba97d2848d34ffdb1f97f0b744457c6811337282b4359a2)\nThe package @evoja-web/create-react-project was found to contain malicious code.\n","modified":"2026-04-23T21:12:06.217953Z","published":"2026-04-16T09:33:46Z","database_specific":{"malicious-packages-origins":[{"sha256":"37d48543af4c6cfb761db9ed635b88bb54a6ddec168c8b442ff65fc1a8642455","import_time":"2026-04-16T15:38:47.931862812Z","source":"reversing-labs","id":"RLMA-2026-01851","versions":["1.0.0","99.0.0"],"modified_time":"2026-04-16T09:33:46Z"},{"sha256":"edb63f2bfa081652aba97d2848d34ffdb1f97f0b744457c6811337282b4359a2","import_time":"2026-04-23T20:48:59.504254458Z","source":"amazon-inspector","versions":["1.0.0","99.0.0"],"modified_time":"2026-04-23T20:43:56Z"}]},"affected":[{"package":{"name":"@evoja-web/create-react-project","ecosystem":"npm","purl":"pkg:npm/%40evoja-web/create-react-project"},"versions":["1.0.0","99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@evoja-web/create-react-project/MAL-2026-2710.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}