{"id":"MAL-2026-906","summary":"Malicious code in cucumber_json_schema (RubyGems)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (f6511110b5695ace5b67288aeb0800934628b5a510045ccf1f62c84011e73951)\nThe OpenSSF Package Analysis project identified 'cucumber_json_schema' @ 90002.0 (rubygems) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","aliases":["GHSA-mg5m-qmr9-mphv"],"modified":"2026-07-23T07:56:21.897716782Z","published":"2026-02-15T14:20:25Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-02-15T14:43:56.159173275Z","modified_time":"2026-02-15T14:20:25Z","sha256":"f6511110b5695ace5b67288aeb0800934628b5a510045ccf1f62c84011e73951","source":"ossf-package-analysis","versions":["90002.0"]}]},"affected":[{"package":{"name":"cucumber_json_schema","ecosystem":"RubyGems","purl":"pkg:gem/cucumber_json_schema"},"versions":["90002.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/cucumber_json_schema/MAL-2026-906.json"}}],"schema_version":"1.7.5","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}