MAL-2025-190610

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wishlist_dropdown/MAL-2025-190610.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-190610
Published
2025-11-22T10:00:55Z
Modified
2025-11-24T16:09:33Z
Summary
Malicious code in wishlist_dropdown (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (96af5d4cffbd1a2bb13ecd403b9acf5e0fe62f6df151c6b511f556c9c0a11c31)

The package wishlist_dropdown was found to contain malicious code.

Source: ossf-package-analysis (540617ab5b0a7271f01ad4fca3eb1988a4c266992332ef26bde224f864929043)

The OpenSSF Package Analysis project identified 'wishlist_dropdown' @ 97.1.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-11-22T10:06:29.10227626Z",
            "modified_time": "2025-11-22T10:00:55Z",
            "sha256": "540617ab5b0a7271f01ad4fca3eb1988a4c266992332ef26bde224f864929043",
            "source": "ossf-package-analysis",
            "versions": [
                "97.1.0"
            ]
        },
        {
            "import_time": "2025-11-24T16:07:33.906307424Z",
            "modified_time": "2025-11-24T15:54:02Z",
            "sha256": "96af5d4cffbd1a2bb13ecd403b9acf5e0fe62f6df151c6b511f556c9c0a11c31",
            "source": "amazon-inspector",
            "versions": [
                "97.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / wishlist_dropdown

Package

Affected ranges

Affected versions

97.*
97.1.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wishlist_dropdown/MAL-2025-190610.json"