{"schema_version":"1.7.3","id":"MAL-2026-848","published":"2026-02-11T03:35:51Z","modified":"2026-02-23T04:34:03.661753Z","summary":"Malicious code in npm_cimetadata (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d1d7a7d39465b33d104fa6608118d45f3077d7a603292dd367135788a47e182d)\nThe package npm_cimetadata was found to contain malicious code.\n\n## Source: ossf-package-analysis (f7970f24b4e05cac8e0692834347b475d4ab966239b6ad39964ac45802ba49cb)\nThe OpenSSF Package Analysis project identified 'npm_cimetadata' @ 0.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","affected":[{"package":{"name":"npm_cimetadata","ecosystem":"npm","purl":"pkg:npm/npm_cimetadata"},"versions":["0.0.1","0.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npm_cimetadata/MAL-2026-848.json"}}],"database_specific":{"malicious-packages-origins":[{"import_time":"2026-02-11T04:20:21.822427393Z","modified_time":"2026-02-11T03:35:51Z","sha256":"f7970f24b4e05cac8e0692834347b475d4ab966239b6ad39964ac45802ba49cb","source":"ossf-package-analysis","versions":["0.0.1"]},{"import_time":"2026-02-11T08:19:24.108515989Z","modified_time":"2026-02-11T08:15:50Z","sha256":"15417f1edc00e00a75d1bd4508447dcb0f65c0e97d819237dc97d1143e975fe2","source":"ossf-package-analysis","versions":["0.0.2"]},{"import_time":"2026-02-23T04:19:44.924951901Z","modified_time":"2026-02-23T03:51:30Z","sha256":"d1d7a7d39465b33d104fa6608118d45f3077d7a603292dd367135788a47e182d","source":"amazon-inspector","versions":["0.0.1","0.0.2"]}]},"credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}