MAL-2023-8013
Dashboard / Malicious Package / MAL-2023-8013
MAL-2023-8013
Summary: Malicious code in binarium-client (npm)
Details: Source: checkmarx (e6203f8ba86eed8c7eef3531a2e69f72fa4badbcd98e90b291436bf574cb24c7) Malicious packages campaign since 2021 targeting developers, steals source code and secrets
References: https://medium.com/checkmarx-security/an-ongoing-open-source-attack-reveals-roots-dating-back-to-2021-4a511979fd98, https://security.snyk.io/vuln/SNYK-JS-BINARIUMCLIENT-5819560, https://blog.phylum.io/targeted-npm-malware-attempts-to-steal-developers-source-code-and-secrets/
Affected packages
Package
Name: binarium-client
Purl: pkg:npm/binarium-client
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
3.0.0-prebuilt
3.0.0
