{"id":"MAL-2026-7206","summary":"Malicious code in apache-arrow-17 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n","aliases":["GHSA-7w3h-4r4c-h494"],"modified":"2026-09-01T11:30:59.531476673Z","published":"2026-07-07T12:38:37Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-09T09:16:16.532329608Z","modified_time":"2026-07-07T12:38:37Z","sha256":"7ffe8f08d6950b2f38036661092d221f007696555cb67cac77d1cc32c0cb6a51","source":"reversing-labs","versions":["9.9.9"],"id":"RLMA-2026-04927"},{"import_time":"2026-09-01T11:17:55.560816332Z","modified_time":"2026-08-24T16:38:59Z","sha256":"6737dd6c10ea51ba2baec78f365904286ed0f4d06a1e1db8a283d96f94f5c17d","source":"reversing-labs","id":"RLUA-2026-06063"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7w3h-4r4c-h494"}],"affected":[{"package":{"name":"apache-arrow-17","ecosystem":"npm","purl":"pkg:npm/apache-arrow-17"},"versions":["9.9.9"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/apache-arrow-17/MAL-2026-7206.json"}}],"schema_version":"1.9.0","credits":[{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}