{"id":"MAL-2026-3329","summary":"Malicious code in api-typings (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a549cfdf0cbbfa203632d6fe432f69fa60578b8d81b03b75c2bece912aa0c588)\nThe package api-typings was found to contain malicious code.\n\n## Source: ossf-package-analysis (f599905f33c2cf15b340aefe57ac68d680d21634484fad6e64ac24aa006e8e97)\nThe OpenSSF Package Analysis project identified 'api-typings' @ 100.2.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-05-12T07:55:58.996934Z","published":"2026-05-04T16:46:38Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-05-04T17:36:20.331584162Z","source":"ossf-package-analysis","modified_time":"2026-05-04T16:46:38Z","versions":["100.2.0"],"sha256":"f599905f33c2cf15b340aefe57ac68d680d21634484fad6e64ac24aa006e8e97"},{"import_time":"2026-05-12T07:28:53.77659933Z","source":"amazon-inspector","modified_time":"2026-05-12T06:53:21Z","versions":["100.2.0"],"sha256":"a549cfdf0cbbfa203632d6fe432f69fa60578b8d81b03b75c2bece912aa0c588"}]},"affected":[{"package":{"name":"api-typings","ecosystem":"npm","purl":"pkg:npm/api-typings"},"versions":["100.2.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/api-typings/MAL-2026-3329.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}