MAL-2026-2003

    Dashboard / Malicious Package / MAL-2026-2003

    MAL-2026-2003

    Published: 20 Mar 2026Last Modified: 23 Mar 2026

    Summary: Malicious code in shakti-strings (npm)

    Details: Source: amazon-inspector (7f2263a09a764a00c111f0baad35ef067d15ac1baaf92efd30cf27d86a4adc66) The package shakti-strings was found to contain malicious code. Source: ossf-package-analysis (aa19f1d5261846b18a1a4f35020c31393119768f0856d30d87677c06fd680fe5) The OpenSSF Package Analysis project identified 'shakti-strings' @ 1.4.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    References:

    Affected packages

    Package

    Name: shakti-strings

    Purl: pkg:npm/shakti-strings

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.4.0
    MAL-2026-2003 | CVE-DB