MAL-2025-191975

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-merry-cookiejar-987/MAL-2025-191975.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191975
Published
2025-12-03T12:55:35Z
Modified
2025-12-23T21:59:20.498963Z
Summary
Malicious code in elf-stats-merry-cookiejar-987 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (75fe8df281f1f2fce72e4cebd7dc37b97562bc7ca5bd5e5ac7da9d78d6e22cb1)

The package elf-stats-merry-cookiejar-987 was found to contain malicious code.

Source: ossf-package-analysis (541a04f56cbd8f31800abc491c053fa5bb6d98930facf5e3cb0a31cbb84a01d6)

The OpenSSF Package Analysis project identified 'elf-stats-merry-cookiejar-987' @ 1.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "541a04f56cbd8f31800abc491c053fa5bb6d98930facf5e3cb0a31cbb84a01d6",
            "modified_time": "2025-12-03T12:55:35Z",
            "versions": [
                "1.0.1"
            ],
            "import_time": "2025-12-03T13:18:21.785828044Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "fdefea934c5ab2ced5d1093bd68c17c817281cbe59d2acda5acebea17178118c",
            "modified_time": "2025-12-03T13:23:19Z",
            "versions": [
                "1.0.4"
            ],
            "import_time": "2025-12-03T13:45:01.388625321Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "75fe8df281f1f2fce72e4cebd7dc37b97562bc7ca5bd5e5ac7da9d78d6e22cb1",
            "modified_time": "2025-12-03T15:59:29Z",
            "versions": [
                "1.0.1",
                "1.0.2",
                "1.0.3",
                "1.0.4",
                "2.0.0"
            ],
            "import_time": "2025-12-03T16:09:37.099685242Z",
            "source": "amazon-inspector"
        },
        {
            "sha256": "c33daf6eece7d9b764a02e7e62c2dec9c22af6ca4a56baea9bcad3fe6fcfe5d7",
            "modified_time": "2025-12-03T13:00:45Z",
            "versions": [
                "1.0.3"
            ],
            "import_time": "2025-12-04T00:27:05.350090621Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "bdd35986eda137035530c93eb632f5b27ea627d1f1218c3601a71e72d728aa3a",
            "modified_time": "2025-12-23T08:09:00Z",
            "id": "RLMA-2025-06232",
            "versions": [
                "1.0.0",
                "1.0.1",
                "1.0.2",
                "1.0.3"
            ],
            "import_time": "2025-12-23T20:38:58.628379244Z",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / elf-stats-merry-cookiejar-987

Package

Name
elf-stats-merry-cookiejar-987
View open source insights on deps.dev
Purl
pkg:npm/elf-stats-merry-cookiejar-987

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
2.*
2.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-merry-cookiejar-987/MAL-2025-191975.json"