{"id":"MAL-2026-3074","summary":"Malicious code in axis-abc-portal-menu (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (84dbd03fbc7970d1f3fc987743f698a9ea6a0af44ea2b89d0f2c1cbaa397f933)\nThe package axis-abc-portal-menu was found to contain malicious code.\n\n## Source: ossf-package-analysis (e394d219d698bd133d0914b1fb257d0a422174497c777a31dab1e5fc55a1b47e)\nThe OpenSSF Package Analysis project identified 'axis-abc-portal-menu' @ 99.99.99 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-05-05T00:07:13.831831Z","published":"2026-04-25T09:45:52Z","database_specific":{"malicious-packages-origins":[{"source":"ossf-package-analysis","sha256":"51849e0e7d00b162d43e21c661c2ab928d218219382a14b8c0235dc101439b09","versions":["1.0.0"],"modified_time":"2026-04-25T09:45:52Z","import_time":"2026-04-27T01:40:40.483613796Z"},{"source":"amazon-inspector","sha256":"84dbd03fbc7970d1f3fc987743f698a9ea6a0af44ea2b89d0f2c1cbaa397f933","versions":["1.0.0"],"modified_time":"2026-04-30T21:59:18Z","import_time":"2026-04-30T22:23:12.375884952Z"},{"source":"ossf-package-analysis","sha256":"e394d219d698bd133d0914b1fb257d0a422174497c777a31dab1e5fc55a1b47e","versions":["99.99.99"],"modified_time":"2026-05-03T12:25:37Z","import_time":"2026-05-04T03:13:21.951776617Z"},{"source":"ossf-package-analysis","sha256":"1b92454a3753c68e1011df3bcf8f965b68941e933f0c00e2b75be438011446bc","versions":["100.0.0"],"modified_time":"2026-05-04T13:30:44Z","import_time":"2026-05-04T23:49:27.560510171Z"}]},"affected":[{"package":{"name":"axis-abc-portal-menu","ecosystem":"npm","purl":"pkg:npm/axis-abc-portal-menu"},"versions":["1.0.0","99.99.99","100.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axis-abc-portal-menu/MAL-2026-3074.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}