MAL-2023-1148
Dashboard / Malicious Package / MAL-2023-1148
MAL-2023-1148
Summary: Malicious code in cptalertbox (npm)
Details: Source: checkmarx (88c1f10ff1d7a9b89a479bd30b9548a7adc533c677f7913c88563b08e9d28814) Malicious packages campaign since 2021 targeting developers, steals source code and secrets Source: ossf-package-analysis (6335c6dc85309d9e802aa0989e277e329a7e87887f9ddba2aeb7db0ebc1772f2) The OpenSSF Package Analysis project identified 'cptalertbox' @ 71.999.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
References: https://medium.com/checkmarx-security/an-ongoing-open-source-attack-reveals-roots-dating-back-to-2021-4a511979fd98, https://security.snyk.io/vuln/SNYK-JS-CPTALERTBOX-5876605
Affected packages
Package
Name: cptalertbox
Purl: pkg:npm/cptalertbox
Affected ranges
Type: SEMVER
Events:
