{"id":"MAL-2026-7047","summary":"Malicious code in @athena-ui-components/pubsub-bridge (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n","aliases":["GHSA-w5gx-prmq-q2cp"],"modified":"2026-09-01T11:30:39.289506599Z","published":"2026-07-07T12:18:37Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-07T12:18:37Z","sha256":"4f62cd6a92c4f9e5c071959f89b1a3510652aafc57cd87e4e06d00e86713a84e","source":"reversing-labs","versions":["0.0.16","0.0.17"],"id":"RLMA-2026-04679","import_time":"2026-07-09T09:15:49.852389228Z"},{"id":"RLUA-2026-05819","import_time":"2026-09-01T11:17:38.990181329Z","modified_time":"2026-08-24T16:19:26Z","sha256":"f25be3aff0d8e797f736b5140b5536cc373678135c492f8bc46badb068be1816","source":"reversing-labs"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w5gx-prmq-q2cp"}],"affected":[{"package":{"name":"@athena-ui-components/pubsub-bridge","ecosystem":"npm","purl":"pkg:npm/%40athena-ui-components/pubsub-bridge"},"versions":["0.0.16","0.0.17"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@athena-ui-components/pubsub-bridge/MAL-2026-7047.json"}}],"schema_version":"1.9.0","credits":[{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}