{"id":"MAL-2024-8736","summary":"Malicious code in @maas-tools/keycloak (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (2e82958168e113d6a4eb9f979c301d52f5df0373ce692f3db35969310bf10af5)\nThe OpenSSF Package Analysis project identified '@maas-tools/keycloak' @ 2.1.5 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2024-09-05T00:20:18Z","published":"2024-09-04T19:00:03Z","database_specific":{"malicious-packages-origins":[{"sha256":"2e82958168e113d6a4eb9f979c301d52f5df0373ce692f3db35969310bf10af5","versions":["2.1.5"],"source":"ossf-package-analysis","import_time":"2024-09-05T00:19:46.886537213Z","modified_time":"2024-09-04T19:21:39Z"},{"sha256":"d7bb3ab65cb258e2e19cb3733c778dd7625d57fa9c5b5ab56c14483293509d09","versions":["2.1.6"],"source":"ossf-package-analysis","import_time":"2024-09-05T00:19:46.970864191Z","modified_time":"2024-09-04T19:25:56Z"},{"sha256":"fbb70474249b0ecf6ee698186fd550bd3326788e9df5c1277e068aff6113274a","versions":["2.1.1"],"source":"ossf-package-analysis","import_time":"2024-09-05T00:19:46.527002092Z","modified_time":"2024-09-04T19:00:03Z"}]},"affected":[{"package":{"name":"@maas-tools/keycloak","ecosystem":"npm","purl":"pkg:npm/%40maas-tools/keycloak"},"versions":["2.1.5","2.1.6","2.1.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@maas-tools/keycloak/MAL-2024-8736.json"}}],"schema_version":"1.7.3","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}