MAL-2025-191577

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/kyjnzu/MAL-2025-191577.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191577
Aliases
  • SNYK-JS-KYJNZU-14152274
Published
2025-12-01T13:15:02Z
Modified
2026-03-19T12:45:29.125228Z
Summary
Malicious code in kyjnzu (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (76ec5839e1ac972ae9271550bfe712c6d00f654ebce392fdc89762ab7347a663)

The package kyjnzu was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "4.2.3"
            ],
            "modified_time": "2025-12-01T13:15:02Z",
            "sha256": "12b690dcafaba865d7e9b50332f5ae3d4393693d7ae12d62993b884e33796393",
            "id": "RLMA-2025-05823",
            "source": "reversing-labs",
            "import_time": "2025-12-02T09:09:48.456584526Z"
        },
        {
            "versions": [
                "4.2.3"
            ],
            "modified_time": "2025-12-02T21:11:00Z",
            "sha256": "76ec5839e1ac972ae9271550bfe712c6d00f654ebce392fdc89762ab7347a663",
            "source": "amazon-inspector",
            "import_time": "2025-12-02T21:35:54.656811544Z"
        },
        {
            "modified_time": "2025-12-23T08:18:51Z",
            "sha256": "f729ff2833952f9a5421d883e1998a5e916e171eb683c3d3750ab9c74f0eb7c9",
            "id": "RLUA-2025-06394",
            "source": "reversing-labs",
            "import_time": "2025-12-24T10:07:34.921822661Z"
        },
        {
            "modified_time": "2026-03-18T12:57:07Z",
            "sha256": "1bd4f664347b99079d463f44d124c228eeef5ea21e51c5353fdd3638f184cb9d",
            "id": "RLUA-2026-01396",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:20:55.769559613Z"
        }
    ]
}
References
Credits

Affected packages

npm / kyjnzu

Package

Affected ranges

Affected versions

4.*
4.2.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/kyjnzu/MAL-2025-191577.json"