{"id":"MAL-2026-2711","summary":"Malicious code in @evoja-web/react-login (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c5a150d97bdfc04cfc9e3ce56a7d6238d57f578628802fa568ea6404b5463070)\nThe package @evoja-web/react-login was found to contain malicious code.\n","modified":"2026-04-23T21:05:00.663458Z","published":"2026-04-16T09:33:48Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-04-16T09:33:48Z","source":"reversing-labs","sha256":"e34fdbf9d8cedd7358099b12b0263c7e68275134a0d031c11fb348c3a79dd62a","import_time":"2026-04-16T15:38:48.066099665Z","versions":["99.0.0"],"id":"RLMA-2026-01852"},{"modified_time":"2026-04-23T20:43:56Z","source":"amazon-inspector","sha256":"c5a150d97bdfc04cfc9e3ce56a7d6238d57f578628802fa568ea6404b5463070","import_time":"2026-04-23T20:49:08.440744125Z","versions":["99.0.0"]}]},"affected":[{"package":{"name":"@evoja-web/react-login","ecosystem":"npm","purl":"pkg:npm/%40evoja-web/react-login"},"versions":["99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@evoja-web/react-login/MAL-2026-2711.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}