MAL-2024-7784
Dashboard / Malicious Package / MAL-2024-7784
MAL-2024-7784
Published: 22 Jul 2024Last Modified: 24 Jul 2024
Summary: Malicious code in jqtools-toolbox-expose (npm)
Details: The package contains code to exfiltrate user and host information to an oastify domain. Source: ossf-package-analysis (cf8ecc5384976555e101e147d0456707c86467e52647ed0bdbc91bc47639356a) The OpenSSF Package Analysis project identified 'jqtools-toolbox-expose' @ 69.69.69 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References:
Affected packages
Package
Name: jqtools-toolbox-expose
Purl: pkg:npm/jqtools-toolbox-expose
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
69.69.69
