Malicious Package Affecting zendesk-api package, versions [1.24.27][1.24.33][1.24.18][1.24.9][1.24.25][1.24.57][1.24.64][1.24.28][1.24.17][1.24.65][1.24.24][1.24.58][1.24.31][1.24.56][1.24.66][1.24.6][1.24.19][1.24.48][1.24.47][1.24.8][1.24.55][1.24.7][1.24.37][1.24.3][1.24.60][1.24.21][1.24.4][1.24.61][1.24.52][12.57.9][1.24.2][12.58.0][1.24.44][1.24.20][1.24.12][1.24.34][1.24.36][12.57.8][1.24.53][1.24.15][1.24.45][1.24.38][1.24.59][1.24.50][1.24.51][1.24.22][1.24.13][1.24.23][1.24.62][1.24.16][1.24.35][1.24.42][1.24.40][1.24.41][1.24.14][1.24.63][1.24.54][1.24.49][1.24.30][1.24.46][1.24.11][1.24.39][1.24.43][1.24.26][1.24.32][1.24.10][1.24.5][1.24.29][1.24.1]


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-ZENDESKAPI-18138140
  • published22 Jul 2026
  • disclosed20 Jul 2026
  • creditUnknown

Introduced: 20 Jul 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the Zendesk-Api package.

Overview

Zendesk-Api is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.

CVSS Base Scores

version 4.0
version 3.1